CVE-2013-2776
published 2013-04-08CVE-2013-2776: sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does…
PriorityP415medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.37%
29.6th percentile
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.
Affected
71 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.4 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | sudo | < sudo 1.8.5p2-1+nmu1 (bookworm) | sudo 1.8.5p2-1+nmu1 (bookworm) |
| sudo_project | sudo | >= 0 < 1.8.5p2-1+nmu1 | 1.8.5p2-1+nmu1 |
| sudo_project | sudo | >= 0 < 1.8.5p2-1+nmu1 | 1.8.5p2-1+nmu1 |
| sudo_project | sudo | >= 0 < 1.8.5p2-1+nmu1 | 1.8.5p2-1+nmu1 |
| sudo_project | sudo | >= 0 < 1.8.5p2-1+nmu1 | 1.8.5p2-1+nmu1 |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
sudo: bypass of tty_tickets constraints
vendor_redhat·2013-02-27·CVSS 4.4
CVE-2013-2776 [MEDIUM] sudo: bypass of tty_tickets constraints
sudo: bypass of tty_tickets constraints
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.
Debian
CVE-2013-2776: sudo - sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems w...
vendor_debian·2013·CVSS 4.4
CVE-2013-2776 [MEDIUM] CVE-2013-2776: sudo - sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems w...
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.
Scope: local
bookworm: resolved (fixed in 1.8.5p2-1+nmu1)
bullseye: resolved (fixed in 1.8.5p2-1+nmu1)
forky: resolved (fixed in 1.8.5p2-1+nmu1)
sid: resolved (fixed in 1.8.5p2-1+nmu1)
trixie: resolved (fixed i
Apple
CVE-2013-2776: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 4.4
CVE-2013-2776 [MEDIUM] CVE-2013-2776: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2013-2776
Component: CVE-2013-2776
GHSA
GHSA-crcj-xh9h-7wr8: sudo 1
ghsa_unreviewed·2022-05-17·CVSS 4.4
CVE-2013-2776 [MEDIUM] GHSA-crcj-xh9h-7wr8: sudo 1
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.
OSV
CVE-2013-2776: sudo 1
osv·2013-04-08·CVSS 4.4
CVE-2013-2776 [MEDIUM] CVE-2013-2776: sudo 1
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2776 sudo: bypass of tty_tickets constraints
bugzilla·2013-04-08·CVSS 4.4
CVE-2013-2776 [MEDIUM] CVE-2013-2776 sudo: bypass of tty_tickets constraints
CVE-2013-2776 sudo: bypass of tty_tickets constraints
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2776 to
the following vulnerability:
Name: CVE-2013-2776
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2776
Assigned: 20130408
Reference: http://www.openwall.com/lists/oss-security/2013/02/27/31
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=916365
Reference: http://www.sudo.ws/repos/sudo/rev/049a12a5cc14
Reference: http://www.sudo.ws/repos/sudo/rev/0c0283d1fafa
Reference: http://www.sudo.ws/sudo/alerts/tty_tickets.html
Reference: http://www.securityfocus.com/bid/58207
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on
systems without /proc or the sysctl function with the tty_tickets
option enabled, does not properly validat
Bugzilla
CVE-2013-1776 sudo: bypass of tty_tickets constraints
bugzilla·2013-02-27·CVSS 4.4
CVE-2013-1776 [MEDIUM] CVE-2013-1776 sudo: bypass of tty_tickets constraints
CVE-2013-1776 sudo: bypass of tty_tickets constraints
From the upstream advisory:
When a user successfully authenticates with sudo, a time stamp file is updated to allow that user to continue running sudo without requiring a password for a preset time period (five minutes by default).
This time stamp file can either be common to all of a user's terminals, or it can be specific to the particular terminal the user authenticated themselves on. The terminal-specific time stamp file behavior can be controlled using the "tty_tickets" option in the sudoers file. This option has been enabled by default since sudo 1.7.4. Prior to sudo 1.7.4, the default was to use a single time stamp for all the user's sessions.
A vulnerability exists because the user can control which terminal the standard inpu
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=701839http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1353.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1701.htmlhttp://www.debian.org/security/2013/dsa-2642http://www.openwall.com/lists/oss-security/2013/02/27/31http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/58207http://www.securityfocus.com/bid/62741http://www.slackware.com/security/viewer.php?l=slackware-security&y=2013&m=slackware-security.517440http://www.sudo.ws/repos/sudo/rev/049a12a5cc14http://www.sudo.ws/repos/sudo/rev/0c0283d1fafahttp://www.sudo.ws/sudo/alerts/tty_tickets.htmlhttps://bugs.launchpad.net/ubuntu/+source/sudo/+bug/87023https://bugzilla.redhat.com/show_bug.cgi?id=916365https://exchange.xforce.ibmcloud.com/vulnerabilities/82453https://support.apple.com/kb/HT205031http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=701839http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1353.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1701.htmlhttp://www.debian.org/security/2013/dsa-2642http://www.openwall.com/lists/oss-security/2013/02/27/31http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/58207http://www.securityfocus.com/bid/62741http://www.slackware.com/security/viewer.php?l=slackware-security&y=2013&m=slackware-security.517440http://www.sudo.ws/repos/sudo/rev/049a12a5cc14http://www.sudo.ws/repos/sudo/rev/0c0283d1fafahttp://www.sudo.ws/sudo/alerts/tty_tickets.htmlhttps://bugs.launchpad.net/ubuntu/+source/sudo/+bug/87023https://bugzilla.redhat.com/show_bug.cgi?id=916365https://exchange.xforce.ibmcloud.com/vulnerabilities/82453https://support.apple.com/kb/HT205031
2013-04-08
Published