Sudo
by Gratisoft
Source repositories
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-3156 | Hig | 0.67 | 7.8 | 0.99 | KEV | Jan 26, 2021 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. | |
| CVE-2009-0034 | Hig | 0.51 | 7.8 | 0.00 | Jan 30, 2009 | parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via… | ||
| CVE-2002-0184 | Hig | 0.47 | 7.8 | 0.01 | May 16, 2002 | Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded. | ||
| CVE-2001-0279 | 0.03 | — | 0.01 | May 3, 2001 | Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges. | |||
| CVE-1999-0958 | 0.00 | — | 0.00 | Jan 12, 1998 | sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack. |
- risk 0.67cvss 7.8epss 0.99
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
- risk 0.51cvss 7.8epss 0.00
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via…
- risk 0.47cvss 7.8epss 0.01
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.
- CVE-2001-0279May 3, 2001risk 0.03cvss —epss 0.01
Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
- CVE-1999-0958Jan 12, 1998risk 0.00cvss —epss 0.00
sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.