CVE-2016-7076

Severity
7.8HIGH
EPSS
0.1%
top 77.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 29
Latest updateMay 13

Description

sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.5 | Impact: 5.9

Affected Packages4 packages

Debiansudo< 1.8.18p1-1+3
Ubuntusudo< 1.8.16-0ubuntu1.6+1
NVDsudo_project/sudo1.6.81.8.18
CVEListV5[unknown]/sudosudo 1.8.18p1

🔴Vulnerability Details

5
GHSA
GHSA-v56m-9vh5-5qh5: sudo before version 12022-05-13
OSV
sudo vulnerabilities2020-09-28
OSV
sudo vulnerabilities2019-05-06
CVEList
CVE-2016-7076: sudo before version 12018-05-29
OSV
CVE-2016-7076: sudo before version 12018-05-29

📋Vendor Advisories

4
Ubuntu
Sudo vulnerabilities2020-09-28
Ubuntu
Sudo vulnerabilities2019-05-06
Red Hat
sudo: noexec bypass via wordexp()2016-10-26
Debian
CVE-2016-7076: sudo - sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restri...2016

💬Community

2
Bugzilla
CVE-2016-7076 sudo: noexec bypass via wordexp() [fedora-all]2016-10-27
Bugzilla
CVE-2016-7076 sudo: noexec bypass via wordexp()2016-10-14
CVE-2016-7076 (HIGH CVSS 7.8) | sudo before version 1.8.18p1 is vul | cvebase.io