7
CVE-2015-8239
- EPSS 0.88%
- Veröffentlicht 10.10.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sudo Project ≫ Sudo Version1.8.8
Sudo Project ≫ Sudo Version1.8.8 Updateb1
Sudo Project ≫ Sudo Version1.8.8 Updateb2
Sudo Project ≫ Sudo Version1.8.8 Updateb3
Sudo Project ≫ Sudo Version1.8.8 Updaterc1
Sudo Project ≫ Sudo Version1.8.9
Sudo Project ≫ Sudo Version1.8.9 Updateb1
Sudo Project ≫ Sudo Version1.8.9 Updateb2
Sudo Project ≫ Sudo Version1.8.9 Updatep1
Sudo Project ≫ Sudo Version1.8.9 Updatep2
Sudo Project ≫ Sudo Version1.8.9 Updatep3
Sudo Project ≫ Sudo Version1.8.9 Updatep4
Sudo Project ≫ Sudo Version1.8.9 Updatep5
Sudo Project ≫ Sudo Version1.8.9 Updaterc1
Sudo Project ≫ Sudo Version1.8.9 Updaterc2
Sudo Project ≫ Sudo Version1.8.10
Sudo Project ≫ Sudo Version1.8.10 Updateb1
Sudo Project ≫ Sudo Version1.8.10 Updateb2
Sudo Project ≫ Sudo Version1.8.10 Updateb3
Sudo Project ≫ Sudo Version1.8.10 Updateb4
Sudo Project ≫ Sudo Version1.8.10 Updatep1
Sudo Project ≫ Sudo Version1.8.10 Updatep2
Sudo Project ≫ Sudo Version1.8.10 Updatep3
Sudo Project ≫ Sudo Version1.8.10 Updaterc1
Sudo Project ≫ Sudo Version1.8.10 Updaterc2
Sudo Project ≫ Sudo Version1.8.10 Updaterc3
Sudo Project ≫ Sudo Version1.8.11
Sudo Project ≫ Sudo Version1.8.11 Updateb1
Sudo Project ≫ Sudo Version1.8.11 Updateb2
Sudo Project ≫ Sudo Version1.8.11 Updateb3
Sudo Project ≫ Sudo Version1.8.11 Updateb4
Sudo Project ≫ Sudo Version1.8.11 Updatep1
Sudo Project ≫ Sudo Version1.8.11 Updatep2
Sudo Project ≫ Sudo Version1.8.11 Updaterc1
Sudo Project ≫ Sudo Version1.8.11 Updaterc2
Sudo Project ≫ Sudo Version1.8.12
Sudo Project ≫ Sudo Version1.8.12 Updateb1
Sudo Project ≫ Sudo Version1.8.12 Updateb2
Sudo Project ≫ Sudo Version1.8.12 Updateb3
Sudo Project ≫ Sudo Version1.8.12 Updaterc1
Sudo Project ≫ Sudo Version1.8.12 Updaterc2
Sudo Project ≫ Sudo Version1.8.13
Sudo Project ≫ Sudo Version1.8.13 Updateb1
Sudo Project ≫ Sudo Version1.8.13 Updateb2
Sudo Project ≫ Sudo Version1.8.13 Updateb3
Sudo Project ≫ Sudo Version1.8.13 Updateb4
Sudo Project ≫ Sudo Version1.8.13 Updaterc1
Sudo Project ≫ Sudo Version1.8.13 Updaterc2
Sudo Project ≫ Sudo Version1.8.14
Sudo Project ≫ Sudo Version1.8.14 Updateb1
Sudo Project ≫ Sudo Version1.8.14 Updateb2
Sudo Project ≫ Sudo Version1.8.14 Updateb3
Sudo Project ≫ Sudo Version1.8.14 Updateb4
Sudo Project ≫ Sudo Version1.8.14 Updatep1
Sudo Project ≫ Sudo Version1.8.14 Updatep2
Sudo Project ≫ Sudo Version1.8.14 Updatep3
Sudo Project ≫ Sudo Version1.8.14 Updaterc1
Sudo Project ≫ Sudo Version1.8.15
Sudo Project ≫ Sudo Version1.8.15 Updateb1
Sudo Project ≫ Sudo Version1.8.15 Updateb2
Sudo Project ≫ Sudo Version1.8.15 Updateb3
Sudo Project ≫ Sudo Version1.8.15 Updateb4
Sudo Project ≫ Sudo Version1.8.15 Updateb5
Sudo Project ≫ Sudo Version1.8.15 Updaterc1
Sudo Project ≫ Sudo Version1.8.15 Updaterc2
Sudo Project ≫ Sudo Version1.8.15 Updaterc3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.88% | 0.731 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7 | 1 | 5.9 |
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.