Sudo
by Sudo Project
Source repositories
CVEs (42)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-27320 | 0.00 | — | 0.02 | Feb 28, 2023 | Sudo before 1.9.13p2 has a double free in the per-command chroot feature. | |||
| CVE-2021-23239 | 0.00 | — | 0.01 | Jan 12, 2021 | The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path. | |||
| CVE-2019-19232 | 0.00 | — | 0.03 | Dec 19, 2019 | In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a… | |||
| CVE-2019-19234 | 0.00 | — | 0.03 | Dec 19, 2019 | In Sudo through 1.8.29, the fact that a user has been blocked (e.g., by using the ! character in the shadow file instead of a password hash) is not considered, allowing an attacker (who has access to a Runas ALL sudoer account) to impersonate any blocked user. NOTE: The software… | |||
| CVE-2005-4890 | 0.00 | — | 0.01 | Nov 4, 2019 | There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process. | |||
| CVE-2019-18684 | 0.00 | — | 0.00 | Nov 4, 2019 | Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process. This occurs because of a race condition between determining a uid, and the setresuid and openat system calls. The attacker can write "ALL ALL=(ALL)… | |||
| CVE-2014-0106 | 0.00 | — | 0.00 | Mar 11, 2014 | Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable. | |||
| CVE-2013-2777 | 0.00 | — | 0.00 | Apr 8, 2013 | sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to a session… | |||
| CVE-2013-2776 | 0.00 | — | 0.00 | Apr 8, 2013 | sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the… | |||
| CVE-2013-1776 | 0.00 | — | 0.00 | Apr 8, 2013 | sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting… | |||
| CVE-2012-2337 | 0.00 | — | 0.00 | May 18, 2012 | sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4… | |||
| CVE-2011-0010 | 0.00 | — | 0.01 | Jan 18, 2011 | check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command. | |||
| CVE-2010-2956 | 0.00 | — | 0.00 | Sep 10, 2010 | Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence. | |||
| CVE-2010-1646 | 0.00 | — | 0.00 | Jun 7, 2010 | The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable. | |||
| CVE-2010-1163 | 0.00 | — | 0.00 | Apr 16, 2010 | The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary… | |||
| CVE-2010-0427 | 0.00 | — | 0.00 | Feb 25, 2010 | sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command. | |||
| CVE-2010-0426 | 0.00 | — | 0.01 | Feb 24, 2010 | sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file,… | |||
| CVE-2007-3149 | 0.00 | — | 0.00 | Jun 11, 2007 | sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE:… | |||
| CVE-2005-2959 | 0.00 | — | 0.01 | Oct 25, 2005 | Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are. | |||
| CVE-2005-1119 | 0.00 | — | 0.00 | May 2, 2005 | Sudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary files via a symlink attack on temporary files. |
- CVE-2023-27320Feb 28, 2023risk 0.00cvss —epss 0.02
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
- CVE-2021-23239Jan 12, 2021risk 0.00cvss —epss 0.01
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.
- CVE-2019-19232Dec 19, 2019risk 0.00cvss —epss 0.03
In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a…
- CVE-2019-19234Dec 19, 2019risk 0.00cvss —epss 0.03
In Sudo through 1.8.29, the fact that a user has been blocked (e.g., by using the ! character in the shadow file instead of a password hash) is not considered, allowing an attacker (who has access to a Runas ALL sudoer account) to impersonate any blocked user. NOTE: The software…
- CVE-2005-4890Nov 4, 2019risk 0.00cvss —epss 0.01
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
- CVE-2019-18684Nov 4, 2019risk 0.00cvss —epss 0.00
Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process. This occurs because of a race condition between determining a uid, and the setresuid and openat system calls. The attacker can write "ALL ALL=(ALL)…
- CVE-2014-0106Mar 11, 2014risk 0.00cvss —epss 0.00
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.
- CVE-2013-2777Apr 8, 2013risk 0.00cvss —epss 0.00
sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to a session…
- CVE-2013-2776Apr 8, 2013risk 0.00cvss —epss 0.00
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the…
- CVE-2013-1776Apr 8, 2013risk 0.00cvss —epss 0.00
sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting…
- CVE-2012-2337May 18, 2012risk 0.00cvss —epss 0.00
sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4…
- CVE-2011-0010Jan 18, 2011risk 0.00cvss —epss 0.01
check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.
- CVE-2010-2956Sep 10, 2010risk 0.00cvss —epss 0.00
Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.
- CVE-2010-1646Jun 7, 2010risk 0.00cvss —epss 0.00
The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.
- CVE-2010-1163Apr 16, 2010risk 0.00cvss —epss 0.00
The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary…
- CVE-2010-0427Feb 25, 2010risk 0.00cvss —epss 0.00
sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.
- CVE-2010-0426Feb 24, 2010risk 0.00cvss —epss 0.01
sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file,…
- CVE-2007-3149Jun 11, 2007risk 0.00cvss —epss 0.00
sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE:…
- CVE-2005-2959Oct 25, 2005risk 0.00cvss —epss 0.01
Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.
- CVE-2005-1119May 2, 2005risk 0.00cvss —epss 0.00
Sudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary files via a symlink attack on temporary files.
Page 2 of 3