CVE-2016-7076
published 2018-05-29CVE-2016-7076: sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a…
PriorityP340high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.49%
39.1th percentile
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.8.18p1-1 (bookworm) | sudo 1.8.18p1-1 (bookworm) |
| sudo_project | sudo | >= 0 < 1.8.18p1-1 | 1.8.18p1-1 |
| sudo_project | sudo | >= 0 < 1.8.18p1-1 | 1.8.18p1-1 |
| sudo_project | sudo | >= 0 < 1.8.18p1-1 | 1.8.18p1-1 |
| sudo_project | sudo | >= 0 < 1.8.18p1-1 | 1.8.18p1-1 |
| sudo_project | sudo | >= 0 < 1.8.16-0ubuntu1.6 | 1.8.16-0ubuntu1.6 |
| sudo_project | sudo | >= 0 < 1.8.9p5-1ubuntu1.5+esm5 | 1.8.9p5-1ubuntu1.5+esm5 |
| sudo_project | sudo | 1.6.8 – 1.8.18 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_ubuntu7.0HIGH
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Sudo vulnerabilities
vendor_ubuntu·2020-09-28·CVSS 7.0
CVE-2016-7032 [HIGH] Sudo vulnerabilities
Title: Sudo vulnerabilities
Summary: Several security issues were fixed in Sudo.
USN-3968-1 fixed several vulnerabilities in Sudo. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Florian Weimer discovered that Sudo incorrectly handled the noexec
restriction when used with certain applications. A local attacker could
possibly use this issue to bypass configured restrictions and execute
arbitrary commands. (CVE-2016-7076, CVE-2016-7032)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Sudo vulnerabilities
vendor_ubuntu·2019-05-06·CVSS 6.4
CVE-2016-7076 [MEDIUM] Sudo vulnerabilities
Title: Sudo vulnerabilities
Summary: Several security issues were fixed in Sudo.
Florian Weimer discovered that Sudo incorrectly handled the noexec
restriction when used with certain applications. A local attacker could
possibly use this issue to bypass configured restrictions and execute
arbitrary commands. (CVE-2016-7076)
It was discovered that Sudo did not properly parse the contents of
/proc/[pid]/stat when attempting to determine its controlling tty. A local
attacker in some configurations could possibly use this to overwrite any
file on the filesystem, bypassing intended permissions. (CVE-2017-1000368)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
sudo: noexec bypass via wordexp()
vendor_redhat·2016-10-26·CVSS 6.4
CVE-2016-7076 [MEDIUM] CWE-184 sudo: noexec bypass via wordexp()
sudo: noexec bypass via wordexp()
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.
It was discovered that the sudo noexec restriction could have been bypassed if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.
Package: sudo (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-7076: sudo - sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restri...
vendor_debian·2016·CVSS 6.4
CVE-2016-7076 [MEDIUM] CVE-2016-7076: sudo - sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restri...
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.
Scope: local
bookworm: resolved (fixed in 1.8.18p1-1)
bullseye: resolved (fixed in 1.8.18p1-1)
forky: resolved (fixed in 1.8.18p1-1)
sid: resolved (fixed in 1.8.18p1-1)
trixie: resolved (fixed in 1.8.18p1-1)
GHSA
GHSA-v56m-9vh5-5qh5: sudo before version 1
ghsa_unreviewed·2022-05-13
CVE-2016-7076 [HIGH] CWE-77 GHSA-v56m-9vh5-5qh5: sudo before version 1
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.
OSV
sudo vulnerabilities
osv·2020-09-28·CVSS 7.0
CVE-2016-7076 [HIGH] sudo vulnerabilities
sudo vulnerabilities
USN-3968-1 fixed several vulnerabilities in Sudo. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Florian Weimer discovered that Sudo incorrectly handled the noexec
restriction when used with certain applications. A local attacker could
possibly use this issue to bypass configured restrictions and execute
arbitrary commands. (CVE-2016-7076, CVE-2016-7032)
OSV
sudo vulnerabilities
osv·2019-05-06·CVSS 7.8
CVE-2016-7076 [HIGH] sudo vulnerabilities
sudo vulnerabilities
Florian Weimer discovered that Sudo incorrectly handled the noexec
restriction when used with certain applications. A local attacker could
possibly use this issue to bypass configured restrictions and execute
arbitrary commands. (CVE-2016-7076)
It was discovered that Sudo did not properly parse the contents of
/proc/[pid]/stat when attempting to determine its controlling tty. A local
attacker in some configurations could possibly use this to overwrite any
file on the filesystem, bypassing intended permissions. (CVE-2017-1000368)
OSV
CVE-2016-7076: sudo before version 1
osv·2018-05-29·CVSS 7.8
CVE-2016-7076 [HIGH] CVE-2016-7076: sudo before version 1
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7076 sudo: noexec bypass via wordexp() [fedora-all]
bugzilla·2016-10-27·CVSS 6.4
CVE-2016-7076 [MEDIUM] CVE-2016-7076 sudo: noexec bypass via wordexp() [fedora-all]
CVE-2016-7076 sudo: noexec bypass via wordexp() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While onl
Bugzilla
CVE-2016-7076 sudo: noexec bypass via wordexp()
bugzilla·2016-10-14·CVSS 7.0
CVE-2016-7076 [HIGH] CVE-2016-7076 sudo: noexec bypass via wordexp()
CVE-2016-7076 sudo: noexec bypass via wordexp()
The sudo allows the use of NOEXEC tag it its configuration to define that program executed via sudo can not execute any other commands. This restriction is implemented via dynamic library which is preloaded for the executed program and which implements wrappers for various exec functions.
It was discovered that the wrapping of exec functions is insufficient to block command execution via glibc APIs that internally call one of the exec functions - system() or popen() (see CVE-2016-7032 tracked via bug 1372830), and wordexp (CVE-2016-7076, tracked via this bug).
This issue was originally tracked under single CVE via bug 1372830, but the CVE assignment was split because of different versions in which problems for system()/popen() and wordexp(
Bugzilla
CVE-2016-7032 sudo: noexec bypass via system() and popen()
bugzilla·2016-09-02·CVSS 7.0
CVE-2016-7032 [HIGH] CVE-2016-7032 sudo: noexec bypass via system() and popen()
CVE-2016-7032 sudo: noexec bypass via system() and popen()
Florian Weimer of Red Hat reports:
the sudoers manual page says this:
EXEC and NOEXEC
If sudo has been compiled with noexec support and the underly‐
ing operating system supports it, the NOEXEC tag can be used to
prevent a dynamically-linked executable from running further
commands itself.
In the following example, user aaron may run /usr/bin/more and
/usr/bin/vi but shell escapes will be disabled.
aaron shanty = NOEXEC: /usr/bin/more, /usr/bin/vi
And:
To enable noexec for a command, use the NOEXEC tag as
documented in the User Specification section above.
Here is that example again:
aaron shanty = NOEXEC: /usr/bin/more, /usr/bin/vi
This allows user aaron to run /usr/bin/more and
/usr/bin/vi with noexec enabled. This wil
http://rhn.redhat.com/errata/RHSA-2016-2872.htmlhttp://www.securityfocus.com/bid/95778https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7076https://security.netapp.com/advisory/ntap-20181127-0002/https://usn.ubuntu.com/3968-1/https://usn.ubuntu.com/3968-3/https://www.sudo.ws/alerts/noexec_wordexp.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2872.htmlhttp://www.securityfocus.com/bid/95778https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7076https://security.netapp.com/advisory/ntap-20181127-0002/https://usn.ubuntu.com/3968-1/https://usn.ubuntu.com/3968-3/https://www.sudo.ws/alerts/noexec_wordexp.html
2018-05-29
Published