Debian Sudo vulnerabilities
46 known vulnerabilities affecting debian/sudo.
Total CVEs
46
CISA KEV
2
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
HIGH13MEDIUM20LOW13
Vulnerabilities
Page 2 of 3
CVE-2017-1000368P3HIGHCVSS 8.2fixed in sudo 1.8.20p1-1.1 (bookworm)2017
CVE-2017-1000368 [HIGH] CVE-2017-1000368: sudo - Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input valida...
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
Scope: local
bookworm: resolved (fixed in 1.8.20p1-1.1)
bullseye: resolved (fixed in 1.8.20p1-1.1)
forky: resolved (fixed in 1.8.20p1-1.1)
sid: resolved (fixed in 1.
debian
CVE-2023-42465P3LOWCVSS 7.0fixed in sudo 1.9.15p2-2 (forky)2023
CVE-2023-42465 [HIGH] CVE-2023-42465: sudo - Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or ...
Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.9.15p2-2)
sid: resolved
debian
CVE-2009-0034P4MEDIUMCVSS 7.8fixed in sudo 1.6.9p17-2 (bookworm)2009
CVE-2009-0034 [HIGH] CVE-2009-0034: sudo - parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system g...
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
Scope: local
bookworm: resolved (fixed in 1.6.9p17-2)
bullseye: resolved (fix
debian
CVE-2022-43995P4LOWCVSS 7.1fixed in sudo 1.9.12p1-1 (bookworm)2022
CVE-2022-43995 [HIGH] CVE-2022-43995: sudo - Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins...
Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler, and p
debian
CVE-2015-8239P4HIGHCVSS 7.0fixed in sudo 1.8.17p1-1 (bookworm)2015
CVE-2015-8239 [HIGH] CVE-2015-8239: sudo - The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local ...
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.
Scope: local
bookworm: resolved (fixed in 1.8.17p1-1)
bullseye: resolved (fixed in 1.8.17p1-1)
forky: resolved (fixed in 1.8.17p1-1)
sid: resolved (fixed in 1.8.17p1-1)
trixie: resolved (fixed i
debian
CVE-2016-7032P4HIGHCVSS 7.0fixed in sudo 1.8.15-1 (bookworm)2016
CVE-2016-7032 [HIGH] CVE-2016-7032: sudo - sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass ...
sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.
Scope: local
bookworm: resolved (fixed in 1.8.15-1)
bullseye: resolved (fixed in 1.8.15-1)
forky: resolved (fixed in 1.8.15-1)
sid: resolved (fixed in 1.8.15-1)
trixie: resolved (fixed in
debian
CVE-2010-0426P4MEDIUMCVSS 6.9fixed in sudo 1.7.2p1-1.2 (bookworm)2010
CVE-2010-0426 [MEDIUM] CVE-2010-0426: sudo - sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is en...
sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.
Scope: local
bookworm:
debian
CVE-2004-1051P4HIGHCVSS 7.2fixed in sudo 1.6.8p3-1 (bookworm)2004
CVE-2004-1051 [HIGH] CVE-2004-1051: sudo - sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "(...
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
Scope: local
bookworm: resolved (fixed in 1.6.8p3-1)
bullseye: resolved (fixed in 1.6.8p3-1)
forky: resolved (fixed in 1.6
debian
CVE-2023-28487P4MEDIUMCVSS 5.3fixed in sudo 1.9.13p1-1 (bookworm)2023
CVE-2023-28487 [MEDIUM] CVE-2023-28487: sudo - Sudo before 1.9.13 does not escape control characters in sudoreplay output.
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
Scope: local
bookworm: resolved (fixed in 1.9.13p1-1)
bullseye: resolved (fixed in 1.9.5p2-3+deb11u3)
forky: resolved (fixed in 1.9.13p1-1)
sid: resolved (fixed in 1.9.13p1-1)
trixie: resolved (fixed in 1.9.13p1-1)
debian
CVE-2023-28486P4MEDIUMCVSS 5.3fixed in sudo 1.9.13p1-1 (bookworm)2023
CVE-2023-28486 [MEDIUM] CVE-2023-28486: sudo - Sudo before 1.9.13 does not escape control characters in log messages.
Sudo before 1.9.13 does not escape control characters in log messages.
Scope: local
bookworm: resolved (fixed in 1.9.13p1-1)
bullseye: resolved (fixed in 1.9.5p2-3+deb11u3)
forky: resolved (fixed in 1.9.13p1-1)
sid: resolved (fixed in 1.9.13p1-1)
trixie: resolved (fixed in 1.9.13p1-1)
debian
CVE-2012-2337P4HIGHCVSS 7.2fixed in sudo 1.8.3p2-1.1 (bookworm)2012
CVE-2012-2337 [HIGH] CVE-2012-2337: sudo - sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly...
sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.
Scope: local
bookworm: resolved (fixed in 1.8.3p2-1.1)
bullseye: resolved (fixed in 1.8
debian
CVE-2010-1163P4MEDIUMCVSS 6.9fixed in sudo 1.7.2p6-1 (bookworm)2010
CVE-2010-1163 [MEDIUM] CVE-2010-1163: sudo - The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not proper...
The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerab
debian
CVE-2006-0151P4MEDIUMCVSS 4.6fixed in sudo 1.6.8p12-1 (bookworm)2006
CVE-2006-0151 [MEDIUM] CVE-2006-0151: sudo - sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment varia...
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
Scope: local
bookworm: resolved (fixed in 1.6.8p12-1)
bullseye: resolved (fixed in 1.6.8p12-1)
forky: resolved (fixed in 1.6.8p12-1)
sid: resolved (fixed in 1.6.8p12-1)
trixie: resolved
debian
CVE-2010-2956P4MEDIUMCVSS 6.2fixed in sudo 1.7.4p4-1 (bookworm)2010
CVE-2010-2956 [MEDIUM] CVE-2010-2956: sudo - Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly ...
Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.
Scope: local
bookworm: resolved (fixed in 1.7.4p4-1)
bullseye: resolved (fixed in 1.7.4p4-1)
forky: resolved (fixed in 1.7.4p4-1)
si
debian
CVE-2010-1646P4MEDIUMCVSS 6.2fixed in sudo 1.7.2p7-1 (bookworm)2010
CVE-2010-1646 [MEDIUM] CVE-2010-1646: sudo - The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 throug...
The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.
Scope: local
bookworm: resolved (fixed in 1.7.2p7-1)
bullseye: resolved (fixed in 1.7.2p7-1)
forky: resolv
debian
CVE-2014-0106P4LOWCVSS 6.6fixed in sudo 1.8.5p2-1 (bookworm)2014
CVE-2014-0106 [MEDIUM] CVE-2014-0106: sudo - Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check env...
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.
Scope: local
bookworm: resolved (fixed in 1.8.5p2-1)
bullseye: resolved (fixed in 1.8.5p2-1)
forky: resolved (fixed i
debian
CVE-2010-0427P4MEDIUMCVSS 4.4fixed in sudo 1.7.0-1 (bookworm)2010
CVE-2010-0427 [MEDIUM] CVE-2010-0427: sudo - sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not prop...
sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.
Scope: local
bookworm: resolved (fixed in 1.7.0-1)
bullseye: resolved (fixed in 1.7.0-1)
forky: resolved (fixed in 1.7.0-1)
sid: resolved (fixed in 1.7.0-1)
trixie: resolved (fixed in 1.7.0-1)
debian
CVE-2011-0010P4MEDIUMCVSS 4.4fixed in sudo 1.7.4p4-6 (bookworm)2011
CVE-2011-0010 [MEDIUM] CVE-2011-0010: sudo - check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not...
check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.
Scope: local
bookworm: resolved (fixed in 1.7.4p4-6)
bullseye: resolved (fixed in 1.7.4p4-6)
debian
CVE-2005-2959P4MEDIUMCVSS 4.6fixed in sudo 1.6.8p9-3 (bookworm)2005
CVE-2005-2959 [MEDIUM] CVE-2005-2959: sudo - Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users ...
Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.
Scope: local
bookworm: resolved (fixed in 1.6.8p9-3)
bullseye: resolved (fixed in 1.6.8p9-3)
forky: res
debian
CVE-2013-2776P4MEDIUMCVSS 4.4fixed in sudo 1.8.5p2-1+nmu1 (bookworm)2013
CVE-2013-2776 [MEDIUM] CVE-2013-2776: sudo - sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems w...
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output
debian