CVE-2016-7032

Severity
7.0HIGH
EPSS
0.0%
top 85.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 14
Latest updateMay 13

Description

sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages3 packages

Debiansudo< 1.8.15-1+3
Ubuntusudo< 1.8.9p5-1ubuntu1.5+esm5
NVDtodd_miller/sudo28 versions+27

🔴Vulnerability Details

4
GHSA
GHSA-wmxc-c63f-gpf8: sudo_noexec2022-05-13
OSV
sudo vulnerabilities2020-09-28
CVEList
CVE-2016-7032: sudo_noexec2017-04-14
OSV
CVE-2016-7032: sudo_noexec2017-04-14

📋Vendor Advisories

3
Ubuntu
Sudo vulnerabilities2020-09-28
Red Hat
sudo: noexec bypass via system() and popen()2016-10-26
Debian
CVE-2016-7032: sudo - sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass ...2016

💬Community

2
Bugzilla
CVE-2016-7076 sudo: noexec bypass via wordexp()2016-10-14
Bugzilla
CVE-2016-7032 sudo: noexec bypass via system() and popen()2016-09-02
CVE-2016-7032 (HIGH CVSS 7) | sudo_noexec.so in Sudo before 1.8.1 | cvebase.io