CVE-2017-1000368
published 2017-06-05CVE-2017-1000368: Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in…
PriorityP335high8.2CVSS 3.0
AVLACLPRHUINSCCHIHAH
EPSS
0.57%
43.6th percentile
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.8.20p1-1.1 (bookworm) | sudo 1.8.20p1-1.1 (bookworm) |
| sudo_project | sudo | <= 1.8.20 | — |
| sudo_project | sudo | — | — |
| sudo_project | sudo | >= 0 < 1.8.20p1-1.1 | 1.8.20p1-1.1 |
| sudo_project | sudo | >= 0 < 1.8.20p1-1.1 | 1.8.20p1-1.1 |
| sudo_project | sudo | >= 0 < 1.8.20p1-1.1 | 1.8.20p1-1.1 |
| sudo_project | sudo | >= 0 < 1.8.20p1-1.1 | 1.8.20p1-1.1 |
| sudo_project | sudo | >= 0 < 1.8.16-0ubuntu1.6 | 1.8.16-0ubuntu1.6 |
| sudo_project | sudo | >= 0 < 1.8.9p5-1ubuntu1.5+esm1 | 1.8.9p5-1ubuntu1.5+esm1 |
CVSS provenance
nvdv3.08.2HIGHCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.2HIGH
vendor_debian8.2HIGH
vendor_ubuntu8.2HIGH
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Sudo vulnerability
vendor_ubuntu·2019-05-29·CVSS 8.2
CVE-2017-1000368 [HIGH] Sudo vulnerability
Title: Sudo vulnerability
Summary: Sudo could be made to overwrite files if it received a specially
crafted input.
USN-3968-1 fixed a vulnerability in Sudo. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Sudo did not properly parse the contents of
/proc/[pid]/stat when attempting to determine its controlling tty. A local
attacker in some configurations could possibly use this to overwrite any
file on the filesystem, bypassing intended permissions. (CVE-2017-1000368)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Sudo vulnerabilities
vendor_ubuntu·2019-05-06·CVSS 6.4
CVE-2016-7076 [MEDIUM] Sudo vulnerabilities
Title: Sudo vulnerabilities
Summary: Several security issues were fixed in Sudo.
Florian Weimer discovered that Sudo incorrectly handled the noexec
restriction when used with certain applications. A local attacker could
possibly use this issue to bypass configured restrictions and execute
arbitrary commands. (CVE-2016-7076)
It was discovered that Sudo did not properly parse the contents of
/proc/[pid]/stat when attempting to determine its controlling tty. A local
attacker in some configurations could possibly use this to overwrite any
file on the filesystem, bypassing intended permissions. (CVE-2017-1000368)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
sudo: Privilege escalation via improper get_process_ttyname() parsing (insufficient fix for CVE-2017-1000367)
vendor_redhat·2017-06-02·CVSS 6.4
CVE-2017-1000368 [MEDIUM] CWE-20 sudo: Privilege escalation via improper get_process_ttyname() parsing (insufficient fix for CVE-2017-1000367)
sudo: Privilege escalation via improper get_process_ttyname() parsing (insufficient fix for CVE-2017-1000367)
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
It was found that the original fix for CVE-2017-1000367 was incomplete. A flaw was found in the way sudo parsed tty information from the process status file in the proc filesystem. A local user with privileges to execute commands via sudo could use this flaw to escalate their privileges to root.
Debian
CVE-2017-1000368: sudo - Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input valida...
vendor_debian·2017·CVSS 8.2
CVE-2017-1000368 [HIGH] CVE-2017-1000368: sudo - Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input valida...
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
Scope: local
bookworm: resolved (fixed in 1.8.20p1-1.1)
bullseye: resolved (fixed in 1.8.20p1-1.1)
forky: resolved (fixed in 1.8.20p1-1.1)
sid: resolved (fixed in 1.8.20p1-1.1)
trixie: resolved (fixed in 1.8.20p1-1.1)
GHSA
GHSA-v7hw-ff58-vxfm: Todd Miller's sudo version 1
ghsa_unreviewed·2022-05-14
CVE-2017-1000368 [HIGH] CWE-20 GHSA-v7hw-ff58-vxfm: Todd Miller's sudo version 1
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
OSV
sudo vulnerability
osv·2019-05-29·CVSS 8.2
CVE-2017-1000368 [HIGH] sudo vulnerability
sudo vulnerability
USN-3968-1 fixed a vulnerability in Sudo. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Sudo did not properly parse the contents of
/proc/[pid]/stat when attempting to determine its controlling tty. A local
attacker in some configurations could possibly use this to overwrite any
file on the filesystem, bypassing intended permissions. (CVE-2017-1000368)
OSV
sudo vulnerabilities
osv·2019-05-06·CVSS 7.8
CVE-2016-7076 [HIGH] sudo vulnerabilities
sudo vulnerabilities
Florian Weimer discovered that Sudo incorrectly handled the noexec
restriction when used with certain applications. A local attacker could
possibly use this issue to bypass configured restrictions and execute
arbitrary commands. (CVE-2016-7076)
It was discovered that Sudo did not properly parse the contents of
/proc/[pid]/stat when attempting to determine its controlling tty. A local
attacker in some configurations could possibly use this to overwrite any
file on the filesystem, bypassing intended permissions. (CVE-2017-1000368)
OSV
CVE-2017-1000368: Todd Miller's sudo version 1
osv·2017-06-05·CVSS 8.2
CVE-2017-1000368 [HIGH] CVE-2017-1000368: Todd Miller's sudo version 1
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/98838https://access.redhat.com/errata/RHSA-2017:1574https://kc.mcafee.com/corporate/index?page=content&id=SB10205https://security.gentoo.org/glsa/201710-04https://usn.ubuntu.com/3968-1/https://usn.ubuntu.com/3968-2/https://www.sudo.ws/alerts/linux_tty.htmlhttp://www.securityfocus.com/bid/98838https://access.redhat.com/errata/RHSA-2017:1574https://kc.mcafee.com/corporate/index?page=content&id=SB10205https://security.gentoo.org/glsa/201710-04https://usn.ubuntu.com/3968-1/https://usn.ubuntu.com/3968-2/https://www.sudo.ws/alerts/linux_tty.html
2017-06-05
Published