7.2

CVE-2012-2337

sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Todd MillerSudo Version1.6
Todd MillerSudo Version1.6.1
Todd MillerSudo Version1.6.2
Todd MillerSudo Version1.6.2p3
Todd MillerSudo Version1.6.3
Todd MillerSudo Version1.6.3_p7
Todd MillerSudo Version1.6.4
Todd MillerSudo Version1.6.4p2
Todd MillerSudo Version1.6.5
Todd MillerSudo Version1.6.6
Todd MillerSudo Version1.6.7
Todd MillerSudo Version1.6.7p5
Todd MillerSudo Version1.6.8
Todd MillerSudo Version1.6.8p12
Todd MillerSudo Version1.6.9
Todd MillerSudo Version1.6.9p20
Todd MillerSudo Version1.6.9p21
Todd MillerSudo Version1.6.9p22
Todd MillerSudo Version1.6.9p23
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.14
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C