cbcvebase.
CVE-2013-1776
published 2013-04-08

CVE-2013-1776: sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which…

PriorityP414medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.37%
30.0th percentile
sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.

Affected

81 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x<= 10.10.4
appleos_x_yosemite_v10.10.5_and_security_update_2015-006
debiansudo< sudo 1.8.5p2-1+nmu1 (bookworm)sudo 1.8.5p2-1+nmu1 (bookworm)
sudo_projectsudo>= 0 < 1.8.5p2-1+nmu11.8.5p2-1+nmu1
sudo_projectsudo>= 0 < 1.8.5p2-1+nmu11.8.5p2-1+nmu1
sudo_projectsudo>= 0 < 1.8.5p2-1+nmu11.8.5p2-1+nmu1
sudo_projectsudo>= 0 < 1.8.5p2-1+nmu11.8.5p2-1+nmu1
todd_millersudo<= 1.7.10p4
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo

CVSS provenance

nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.