- EPSS 0.04%
- Veröffentlicht 14.04.2017 18:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.
CVE-2014-0106
- EPSS 0.07%
- Veröffentlicht 11.03.2014 19:37:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variab...
CVE-2013-2777
- EPSS 0.05%
- Veröffentlicht 08.04.2013 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vect...
CVE-2013-2776
- EPSS 0.08%
- Veröffentlicht 08.04.2013 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo pe...
CVE-2013-1776
- EPSS 0.05%
- Veröffentlicht 08.04.2013 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via ...
CVE-2013-1775
- EPSS 2.05%
- Veröffentlicht 05.03.2013 21:38:56
- Zuletzt bearbeitet 11.04.2025 00:51:21
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp t...
CVE-2012-3440
- EPSS 0.12%
- Veröffentlicht 08.08.2012 10:26:19
- Zuletzt bearbeitet 11.04.2025 00:51:21
A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.
CVE-2012-2337
- EPSS 0.05%
- Veröffentlicht 18.05.2012 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command ...
CVE-2012-0809
- EPSS 43.58%
- Veröffentlicht 01.02.2012 00:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.
CVE-2011-0008
- EPSS 0.05%
- Veröffentlicht 20.01.2011 19:00:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to...