Description
sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.
CVSS vector
AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0 Affected Packages2 packages
▶Debiansudo< 1.8.3p2-1.1+3 🔴Vulnerability Details
3GHSAGHSA-69qw-r4p8-f6hq: sudo 1↗2022-05-14 ▶ OSVCVE-2012-2337: sudo 1↗2012-05-18 ▶ CVEListCVE-2012-2337: sudo 1↗2012-05-18 ▶ 📋Vendor Advisories
3Red Hatsudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access↗2012-05-16 ▶ UbuntuSudo vulnerability↗2012-05-16 ▶ DebianCVE-2012-2337: sudo - sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly...↗2012 ▶ 💬Community
2BugzillaCVE-2012-2337 sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access [fedora-all]↗2012-05-16 ▶ BugzillaCVE-2012-2337 sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access↗2012-05-10 ▶