CVE-2014-9680
published 2017-04-24CVE-2014-9680: sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for…
PriorityP412low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.47%
38.0th percentile
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | sudo | < sudo 1.8.12-1 (bookworm) | sudo 1.8.12-1 (bookworm) |
| sudo_project | sudo | <= 1.8.11 | — |
| sudo_project | sudo | >= 0 < 1.8.12-1 | 1.8.12-1 |
| sudo_project | sudo | >= 0 < 1.8.12-1 | 1.8.12-1 |
| sudo_project | sudo | >= 0 < 1.8.12-1 | 1.8.12-1 |
| sudo_project | sudo | >= 0 < 1.8.12-1 | 1.8.12-1 |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xgww-w8fw-rw7h: sudo before 1
ghsa_unreviewed·2022-05-14
CVE-2014-9680 [LOW] CWE-200 GHSA-xgww-w8fw-rw7h: sudo before 1
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.
OSV
CVE-2014-9680: sudo before 1
osv·2017-04-24·CVSS 3.3
CVE-2014-9680 [LOW] CVE-2014-9680: sudo before 1
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.
Ubuntu
Sudo vulnerability
vendor_ubuntu·2015-03-16
CVE-2014-9680 Sudo vulnerability
Title: Sudo vulnerability
Summary: Sudo would allow unintended access to files.
Jakub Wilk and Stephane Chazelas discovered that Sudo incorrectly handled
the TZ environment variable. An attacker with Sudo access could possibly
use this issue to open arbitrary files, bypassing intended permissions.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
sudo: unsafe handling of TZ environment variable
vendor_redhat·2014-10-16·CVSS 3.3
CVE-2014-9680 [LOW] CWE-20 sudo: unsafe handling of TZ environment variable
sudo: unsafe handling of TZ environment variable
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.
It was discovered that sudo did not perform any checks of the TZ environment variable value. If sudo was configured to preserve the TZ environment variable, a local user with privileges to execute commands via sudo could possibly use this flaw to achieve system state changes not permitted by the configured commands.
Note: The default sudoers configuration in Red Hat Enterprise Linux remov
Debian
CVE-2014-9680: sudo - sudo before 1.8.12 does not ensure that the TZ environment variable is associate...
vendor_debian·2014·CVSS 3.3
CVE-2014-9680 [LOW] CVE-2014-9680: sudo - sudo before 1.8.12 does not ensure that the TZ environment variable is associate...
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.
Scope: local
bookworm: resolved (fixed in 1.8.12-1)
bullseye: resolved (fixed in 1.8.12-1)
forky: resolved (fixed in 1.8.12-1)
sid: resolved (fixed in 1.8.12-1)
trixie: resolved (fixed in 1.8.12-1)
Apple
CVE-2014-9680: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 3.3
CVE-2014-9680 [LOW] CVE-2014-9680: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2014-9680
Component: CVE-2014-9680
Impact: Multiple vulnerabilities existed in tcpdump 4.7.3, the most serious of which may allow a remote attacker to cause a denial of service.
Description: Multiple vulnerabilities existed in tcpdump versions prior to 4.7.3. These were addressed by updating tcpdump to version 4.7.3.
No detection rules found.
No public exploits indexed.
Bugzilla
procmail: unsafe handling of TZ environment variable
bugzilla·2015-02-12·CVSS 3.3
CVE-2014-9680 [LOW] procmail: unsafe handling of TZ environment variable
procmail: unsafe handling of TZ environment variable
It is reported that procmail has a similar flaw to sudo's CVE-2014-9680 in that procmail whitelists TZ values incorrectly.
External references:
http://openwall.com/lists/oss-security/2014/10/15/24
https://sources.debian.net/src/procmail/3.22-20%2Bdeb7u1/config.h/?hl=22#L13
http://seclists.org/oss-sec/2015/q1/533
Discussion:
Created procmail tracking bugs for this issue:
Affects: fedora-all [bug 1203601]
---
CVE-2014-9681 has been rejected. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.
Bugzilla
CVE-2014-9680 sudo: unsafe handling of TZ environment variable
bugzilla·2015-02-10·CVSS 3.3
CVE-2014-9680 [LOW] CVE-2014-9680 sudo: unsafe handling of TZ environment variable
CVE-2014-9680 sudo: unsafe handling of TZ environment variable
sudo 1.8.12 will be released shortly [1] which includes sanity checks for the TZ environment variable.
This issue was previously discussed here:
http://www.openwall.com/lists/oss-security/2014/10/15/24
There is an associated Debian bug:
https://bugs.debian.org/772707
From http://www.sudo.ws/alerts/tz.html
Summary:
Prior to sudo 1.8.12, the TZ environment variable was passed through
unchecked. Most libc tzset() implementations support passing an
absolute pathname in the time zone to point to an arbitrary,
user-controlled file. This may be used to exploit bugs in the C
library's TZ parser or open files the user would not otherwise have
access to. Arbitrary file access via TZ could also be used in a
denial of service attack
http://openwall.com/lists/oss-security/2014/10/15/24http://rhn.redhat.com/errata/RHSA-2015-1409.htmlhttp://www.securitytracker.com/id/1033158http://www.sudo.ws/alerts/tz.htmlhttps://security.gentoo.org/glsa/201504-02http://openwall.com/lists/oss-security/2014/10/15/24http://rhn.redhat.com/errata/RHSA-2015-1409.htmlhttp://www.securitytracker.com/id/1033158http://www.sudo.ws/alerts/tz.htmlhttps://security.gentoo.org/glsa/201504-02
2017-04-24
Published