CVE-2015-8239
published 2017-10-10CVE-2015-8239: The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them…
PriorityP428high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.54%
42.2th percentile
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.8.17p1-1 (bookworm) | sudo 1.8.17p1-1 (bookworm) |
| sudo_project | sudo | — | — |
| sudo_project | sudo | — | — |
| sudo_project | sudo | — | — |
| sudo_project | sudo | — | — |
| sudo_project | sudo | — | — |
| sudo_project | sudo | — | — |
| sudo_project | sudo | — | — |
| sudo_project | sudo | — | — |
| sudo_project | sudo | >= 0 < 1.8.17p1-1 | 1.8.17p1-1 |
| sudo_project | sudo | >= 0 < 1.8.17p1-1 | 1.8.17p1-1 |
| sudo_project | sudo | >= 0 < 1.8.17p1-1 | 1.8.17p1-1 |
| sudo_project | sudo | >= 0 < 1.8.17p1-1 | 1.8.17p1-1 |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
sudo: Race condition when checking digests in sudoers
vendor_redhat·2015-11-09·CVSS 7.0
CVE-2015-8239 [HIGH] CWE-367 sudo: Race condition when checking digests in sudoers
sudo: Race condition when checking digests in sudoers
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.
Package: sudo (Red Hat Enterprise Linux 5) - Not affected
Package: sudo (Red Hat Enterprise Linux 6) - Not affected
Package: sudo (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-8239: sudo - The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local ...
vendor_debian·2015·CVSS 7.0
CVE-2015-8239 [HIGH] CVE-2015-8239: sudo - The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local ...
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.
Scope: local
bookworm: resolved (fixed in 1.8.17p1-1)
bullseye: resolved (fixed in 1.8.17p1-1)
forky: resolved (fixed in 1.8.17p1-1)
sid: resolved (fixed in 1.8.17p1-1)
trixie: resolved (fixed in 1.8.17p1-1)
GHSA
GHSA-w2j3-vrwq-vgh5: The SHA-2 digest support in the sudoers plugin in sudo after 1
ghsa_unreviewed·2022-05-17
CVE-2015-8239 [HIGH] CWE-362 GHSA-w2j3-vrwq-vgh5: The SHA-2 digest support in the sudoers plugin in sudo after 1
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.
OSV
CVE-2015-8239: The SHA-2 digest support in the sudoers plugin in sudo after 1
osv·2017-10-10·CVSS 7.0
CVE-2015-8239 [HIGH] CVE-2015-8239: The SHA-2 digest support in the sudoers plugin in sudo after 1
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8239 sudo: Race condition when checking digests in sudoers [fedora-all]
bugzilla·2015-11-19·CVSS 7.0
CVE-2015-8239 [HIGH] CVE-2015-8239 sudo: Race condition when checking digests in sudoers [fedora-all]
CVE-2015-8239 sudo: Race condition when checking digests in sudoers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2015-8239 sudo: Race condition when checking digests in sudoers
bugzilla·2015-11-19·CVSS 7.0
CVE-2015-8239 [HIGH] CVE-2015-8239 sudo: Race condition when checking digests in sudoers
CVE-2015-8239 sudo: Race condition when checking digests in sudoers
A vulnerability in functionality for adding support of SHA-2 digests along with the command was found. The sudoers plugin performs this digest verification while matching rules, and later independently calls execve() to execute the binary. This results in a race condition if the digest functionality is used as suggested (in fact, the rules are matched before the user is prompted for a password, so there is not negligible time frame to replace the binary from underneath sudo). Versions affected are since 1.8.7.
CVE assignment:
http://seclists.org/oss-sec/2015/q4/327
Discussion:
Created sudo tracking bugs for this issue:
Affects: fedora-all [bug 1283636]
---
(In reply to Adam Mariš from comment #2)
> Statement:
>
> N
http://www.openwall.com/lists/oss-security/2015/11/18/22https://bugzilla.redhat.com/show_bug.cgi?id=1283635https://www.sudo.ws/repos/sudo/rev/0cd3cc8fa195https://www.sudo.ws/repos/sudo/rev/24a3d9215c64https://www.sudo.ws/repos/sudo/rev/397722cdd7echttp://www.openwall.com/lists/oss-security/2015/11/18/22https://bugzilla.redhat.com/show_bug.cgi?id=1283635https://www.sudo.ws/repos/sudo/rev/0cd3cc8fa195https://www.sudo.ws/repos/sudo/rev/24a3d9215c64https://www.sudo.ws/repos/sudo/rev/397722cdd7ec
2017-10-10
Published