CVE-2012-2337
published 2012-05-18CVE-2012-2337: sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to…
PriorityP424high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.40%
32.5th percentile
sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.8.3p2-1.1 (bookworm) | sudo 1.8.3p2-1.1 (bookworm) |
| sudo_project | sudo | >= 0 < 1.8.3p2-1.1 | 1.8.3p2-1.1 |
| sudo_project | sudo | >= 0 < 1.8.3p2-1.1 | 1.8.3p2-1.1 |
| sudo_project | sudo | >= 0 < 1.8.3p2-1.1 | 1.8.3p2-1.1 |
| sudo_project | sudo | >= 0 < 1.8.3p2-1.1 | 1.8.3p2-1.1 |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| vmware | esxi | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-69qw-r4p8-f6hq: sudo 1
ghsa_unreviewed·2022-05-14
CVE-2012-2337 [HIGH] GHSA-69qw-r4p8-f6hq: sudo 1
sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.
OSV
CVE-2012-2337: sudo 1
osv·2012-05-18·CVSS 7.2
CVE-2012-2337 [HIGH] CVE-2012-2337: sudo 1
sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.
VMware
VMware security updates for vCenter Server
vendor_vmware·2013-04-25·CVSS 7.2
CVE-2012-2337 [HIGH] VMware security updates for vCenter Server
VMSA-2013-0006: VMware security updates for vCenter Server
a. vCenter Server AD anonymous LDAP binding credential by-pass vCenter Server when deployed in an environment that uses Active Directory (AD) with anonymous LDAP binding enabled doesn't properly handle login credentials. In this environment, authenticating to vCenter Server with a valid user name and a blank password may be successful even if a non-blank password is required for the account. The issue is present on vCenter Server 5.1, 5.1a and 5.1b if AD anonymous LDAP binding is enabled. The issue is addressed in vCenter Server 5.1 Update 1 by removing the possibility to authenticate using blank passwords. This change in the authentication mechanism is present regardless if anonymous binding is enabled or not.
CVEs: CVE-2012-233
Red Hat
sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access
vendor_redhat·2012-05-16·CVSS 7.2
CVE-2012-2337 [HIGH] sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access
sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access
sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.
Ubuntu
Sudo vulnerability
vendor_ubuntu·2012-05-16
CVE-2012-2337 Sudo vulnerability
Title: Sudo vulnerability
Summary: Sudo could allow users to run arbitrary programs as the administrator.
It was discovered that sudo incorrectly handled network masks when using Host
and Host_List. A local user who is listed in sudoers may be allowed to run
commands on unintended hosts when IPv4 network masks are used to grant access.
A local attacker could exploit this to bypass intended access restrictions. Host
and Host_List are not used in the default installation of Ubuntu.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-2337: sudo - sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly...
vendor_debian·2012·CVSS 7.2
CVE-2012-2337 [HIGH] CVE-2012-2337: sudo - sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly...
sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.
Scope: local
bookworm: resolved (fixed in 1.8.3p2-1.1)
bullseye: resolved (fixed in 1.8.3p2-1.1)
forky: resolved (fixed in 1.8.3p2-1.1)
sid: resolved (fixed in 1.8.3p2-1.1)
trixie: resolved (fixed in 1.8.3p2-1.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2337 sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access [fedora-all]
bugzilla·2012-05-16·CVSS 7.2
CVE-2012-2337 [HIGH] CVE-2012-2337 sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access [fedora-all]
CVE-2012-2337 sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
htt
Bugzilla
CVE-2012-2337 sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access
bugzilla·2012-05-10·CVSS 7.2
CVE-2012-2337 [HIGH] CVE-2012-2337 sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access
CVE-2012-2337 sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access
A security flaw was found in the way sudo granted access for particular host, when multiple netmask values have been used in sudo's Host / Host_List configuration. Such configuration allowed unprivileged users, who were authorized by the sudoers file to run their sudo commands, to run these commands from any host regardless of the Host_List configuration (even from hosts, which were intended according to the Host_List netmask configuration not to allow execution of such commands according to the netmask).
Discussion:
This issue affects the versions of the sudo package, as shipped with Red Hat Enterprise Linux 5 and 6.
--
This issue affects the versions of the sudo pac
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081432.htmlhttp://secunia.com/advisories/49219http://secunia.com/advisories/49244http://secunia.com/advisories/49291http://secunia.com/advisories/49948http://www.debian.org/security/2012/dsa-2478http://www.mandriva.com/security/advisories?name=MDVSA-2012:079http://www.securitytracker.com/id?1027077http://www.sudo.ws/sudo/alerts/netmask.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=820677https://www.suse.com/security/cve/CVE-2012-2337/http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081432.htmlhttp://secunia.com/advisories/49219http://secunia.com/advisories/49244http://secunia.com/advisories/49291http://secunia.com/advisories/49948http://www.debian.org/security/2012/dsa-2478http://www.mandriva.com/security/advisories?name=MDVSA-2012:079http://www.securitytracker.com/id?1027077http://www.sudo.ws/sudo/alerts/netmask.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=820677https://www.suse.com/security/cve/CVE-2012-2337/
2012-05-18
Published