cbcvebase.

Debian Sudo vulnerabilities

46 known vulnerabilities affecting debian/sudo.

Total CVEs
46
CISA KEV
2
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
HIGH13MEDIUM20LOW13

Vulnerabilities

Page 3 of 3
CVE-2013-1776P4MEDIUMCVSS 4.4fixed in sudo 1.8.5p2-1+nmu1 (bookworm)2013
CVE-2013-1776 [MEDIUM] CVE-2013-1776: sudo - sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option i... sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this i
debian
CVE-2013-2777P4MEDIUMCVSS 4.4fixed in sudo 1.8.5p2-1+nmu1 (bookworm)2013
CVE-2013-2777 [MEDIUM] CVE-2013-2777: sudo - sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is en... sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to a session without a controlling terminal device and connecting to the standard input, output, and error fi
debian
CVE-2005-1993P4MEDIUMCVSS 3.7fixed in sudo 1.6.8p9-1 (bookworm)2005
CVE-2005-1993 [LOW] CVE-2005-1993: sudo - Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used ... Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack. Scope: local bookworm: resolved (fixed in 1.6.8p9-1) bullseye: resolved (fixed in 1.6.8p9-1) forky: resolved (fixed in 1.6.8p9-1) sid: resolved (fixed in 1.6.8p9-1) trixie: resolved (fixed in 1.
debian
CVE-2014-9680P4LOWCVSS 3.3fixed in sudo 1.8.12-1 (bookworm)2014
CVE-2014-9680 [LOW] CVE-2014-9680: sudo - sudo before 1.8.12 does not ensure that the TZ environment variable is associate... sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives. Scope: local boo
debian
CVE-2021-23239P4LOWCVSS 2.5fixed in sudo 1.9.5-1 (bookworm)2021
CVE-2021-23239 [LOW] CVE-2021-23239: sudo - The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged use... The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path. Scope: local bookworm: resolved (fixed in 1.9.5-1) bullseye: resolved (fixed in 1.9.5-1) forky: resolved (fixed in 1.9.5-1) sid
debian
CVE-2008-3067P4LOWCVSS 2.1fixed in sudo 1.6.9p12-1 (bookworm)2008
CVE-2008-3067 [LOW] CVE-2008-3067: sudo - sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry t... sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits. Scope: local bookworm: resolved (fixed in 1.6.9p12-1) bullseye: resolved (fixed in 1.6.9p12-1) forky: resolved (fixed in 1.6.9p12-1) sid: resolved (fixed in 1
debian
Debian Sudo vulnerabilities | cvebase