Severity
3.3LOW
EPSS
0.4%
top 38.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 24
Latest updateMay 14

Description

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

Debiansudo< 1.8.12-1+3
NVDsudo_project/sudo1.8.11

🔴Vulnerability Details

3
GHSA
GHSA-xgww-w8fw-rw7h: sudo before 12022-05-14
CVEList
CVE-2014-9680: sudo before 12017-04-24
OSV
CVE-2014-9680: sudo before 12017-04-24

📋Vendor Advisories

4
Ubuntu
Sudo vulnerability2015-03-16
Red Hat
sudo: unsafe handling of TZ environment variable2014-10-16
Debian
CVE-2014-9680: sudo - sudo before 1.8.12 does not ensure that the TZ environment variable is associate...2014
Apple
CVE-2014-9680: OS X Yosemite v10.10.5 and Security Update 2015-006

💬Community

2
Bugzilla
procmail: unsafe handling of TZ environment variable2015-02-12
Bugzilla
CVE-2014-9680 sudo: unsafe handling of TZ environment variable2015-02-10
CVE-2014-9680 (LOW CVSS 3.3) | sudo before 1.8.12 does not ensure | cvebase.io