cbcvebase.

Debian Sudo vulnerabilities

52 known vulnerabilities affecting debian/sudo.

Total CVEs
52
CISA KEV
2
actively exploited
Public exploits
12
Exploited in wild
1
Severity breakdown
HIGH13MEDIUM20LOW19

Vulnerabilities

Page 2 of 3
CVE-2016-7076MEDIUMCVSS 6.4fixed in sudo 1.8.18p1-1 (bookworm)2016
CVE-2016-7076 [MEDIUM] CVE-2016-7076: sudo - sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restri... sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges. Scope: local bookworm:
debian
CVE-2016-7091LOWCVSS 4.42016
CVE-2016-7091 [MEDIUM] CVE-2016-7091: sudo - sudo: It was discovered that the default sudo configuration on Red Hat Enterpris... sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges pr
debian
CVE-2015-8239HIGHCVSS 7.0fixed in sudo 1.8.17p1-1 (bookworm)2015
CVE-2015-8239 [HIGH] CVE-2015-8239: sudo - The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local ... The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed. Scope: local bookworm: resolved (fixed in 1.8.17p1-1) bullseye: resolved (fixed in 1.8.17p1-1) forky: resolved (fixed in 1.8.17p1-1) sid: resolved (fixed in 1.8.17p1-1) trixie: resolved (fixed i
debian
CVE-2015-5602HIGHCVSS 7.2PoCfixed in sudo 1.8.15-1.1 (bookworm)2015
CVE-2015-5602 [HIGH] CVE-2015-5602: sudo - sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symli... sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt." Scope: local bookworm: resolved (fixed in 1.8.15-1.1) bullseye: resolved (fixed in 1.8.15-1.1) forky: resolved (fixed in 1.8.15-1.1) sid: resolved (fixed in 1.8.15
debian
CVE-2014-0106LOWCVSS 6.6fixed in sudo 1.8.5p2-1 (bookworm)2014
CVE-2014-0106 [MEDIUM] CVE-2014-0106: sudo - Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check env... Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable. Scope: local bookworm: resolved (fixed in 1.8.5p2-1) bullseye: resolved (fixed in 1.8.5p2-1) forky: resolved (fixed i
debian
CVE-2014-9680LOWCVSS 3.3fixed in sudo 1.8.12-1 (bookworm)2014
CVE-2014-9680 [LOW] CVE-2014-9680: sudo - sudo before 1.8.12 does not ensure that the TZ environment variable is associate... sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives. Scope: local boo
debian
CVE-2013-1776MEDIUMCVSS 4.4fixed in sudo 1.8.5p2-1+nmu1 (bookworm)2013
CVE-2013-1776 [MEDIUM] CVE-2013-1776: sudo - sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option i... sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this i
debian
CVE-2013-1775MEDIUMCVSS 6.9PoCfixed in sudo 1.8.5p2-1+nmu1 (bookworm)2013
CVE-2013-1775 [MEDIUM] CVE-2013-1775: sudo - sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or... sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch. Scope: local bookworm: resolved (fixed in 1.8.5p2-1+nmu1) bullseye: resolved (fixed in 1.8.5p2-1+nmu1) forky
debian
CVE-2013-2777MEDIUMCVSS 4.4fixed in sudo 1.8.5p2-1+nmu1 (bookworm)2013
CVE-2013-2777 [MEDIUM] CVE-2013-2777: sudo - sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is en... sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to a session without a controlling terminal device and connecting to the standard input, output, and error fi
debian
CVE-2013-2776MEDIUMCVSS 4.4fixed in sudo 1.8.5p2-1+nmu1 (bookworm)2013
CVE-2013-2776 [MEDIUM] CVE-2013-2776: sudo - sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems w... sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output
debian
CVE-2012-0809HIGHCVSS 7.2PoCfixed in sudo 1.8.3p2-1 (bookworm)2012
CVE-2012-0809 [HIGH] CVE-2012-0809: sudo - Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8... Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo. Scope: local bookworm: resolved (fixed in 1.8.3p2-1) bullseye: resolved (fixed in 1.8.3p2-1) forky: resolved (fixed in 1.8.3p2-1) sid: resolved (fixed in 1.8.3p2-1) trixie: resolved (fi
debian
CVE-2012-2337HIGHCVSS 7.2fixed in sudo 1.8.3p2-1.1 (bookworm)2012
CVE-2012-2337 [HIGH] CVE-2012-2337: sudo - sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly... sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address. Scope: local bookworm: resolved (fixed in 1.8.3p2-1.1) bullseye: resolved (fixed in 1.8
debian
CVE-2012-3440LOWCVSS 5.62012
CVE-2012-3440 [MEDIUM] CVE-2012-3440: sudo - A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 all... A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2011-0010MEDIUMCVSS 4.4fixed in sudo 1.7.4p4-6 (bookworm)2011
CVE-2011-0010 [MEDIUM] CVE-2011-0010: sudo - check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not... check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command. Scope: local bookworm: resolved (fixed in 1.7.4p4-6) bullseye: resolved (fixed in 1.7.4p4-6)
debian
CVE-2011-0008LOWCVSS 7.82011
CVE-2011-0008 [HIGH] CVE-2011-0008: sudo - A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 do... A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command. NOTE: this vulnerability exists because o
debian
CVE-2010-0427MEDIUMCVSS 4.4fixed in sudo 1.7.0-1 (bookworm)2010
CVE-2010-0427 [MEDIUM] CVE-2010-0427: sudo - sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not prop... sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command. Scope: local bookworm: resolved (fixed in 1.7.0-1) bullseye: resolved (fixed in 1.7.0-1) forky: resolved (fixed in 1.7.0-1) sid: resolved (fixed in 1.7.0-1) trixie: resolved (fixed in 1.7.0-1)
debian
CVE-2010-2956MEDIUMCVSS 6.2fixed in sudo 1.7.4p4-1 (bookworm)2010
CVE-2010-2956 [MEDIUM] CVE-2010-2956: sudo - Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly ... Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence. Scope: local bookworm: resolved (fixed in 1.7.4p4-1) bullseye: resolved (fixed in 1.7.4p4-1) forky: resolved (fixed in 1.7.4p4-1) si
debian
CVE-2010-1646MEDIUMCVSS 6.2fixed in sudo 1.7.2p7-1 (bookworm)2010
CVE-2010-1646 [MEDIUM] CVE-2010-1646: sudo - The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 throug... The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable. Scope: local bookworm: resolved (fixed in 1.7.2p7-1) bullseye: resolved (fixed in 1.7.2p7-1) forky: resolv
debian
CVE-2010-0426MEDIUMCVSS 6.9fixed in sudo 1.7.2p1-1.2 (bookworm)2010
CVE-2010-0426 [MEDIUM] CVE-2010-0426: sudo - sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is en... sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory. Scope: local bookworm:
debian
CVE-2010-1163MEDIUMCVSS 6.9fixed in sudo 1.7.2p6-1 (bookworm)2010
CVE-2010-1163 [MEDIUM] CVE-2010-1163: sudo - The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not proper... The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerab
debian