sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sudo | Aug 30, 2017 | May 18, 2012 |
| Centos_linux | — | Upgrade sudo | Dec 1, 2016 | May 18, 2012 |
| Debian | — | Upgrade sudo | Jul 30, 2024 | May 18, 2012 |
| Freebsd | — | Upgrade sudo | Dec 10, 2025 | May 16, 2012 |
| Gentoo Linux | — | Upgrade app-admin/sudo. | Oct 30, 2017 | May 18, 2012 |
| Oracle Solaris | — | Upgrade security/sudo to version 1.8.4.5-0.175.0.9.0.3.0 on Solaris 11.0 | May 29, 2017 | May 18, 2012 |
| Oracle_linux | — | Upgrade sudo | Oct 16, 2024 | May 18, 2012 |
| Suse | — | Upgrade sudo-plugin-pythonUpgrade system-group-sudoUpgrade sudo-develUpgrade sudoUpgrade sudo-policy-wheel-auth-selfUpgrade sudo-policy-sudo-auth-self | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade sudoUpgrade sudo-ldap | Nov 8, 2024 | May 18, 2012 |
| Vmsa 2013 0007 | — | Upgrade VMware ESX 4.0 to build number 1070634Upgrade VMware ESX 4.1 to build number 1363503 | Jun 14, 2013 | May 18, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub