sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sudo | Aug 30, 2017 | Mar 5, 2013 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2015-006 | Aug 28, 2015 | Mar 5, 2013 |
| Apple Osx Sudo | — | Upgrade macOS to the latest versionApply OS X security update 2013-004 | Sep 17, 2013 | Mar 5, 2013 |
| Debian | — | Upgrade sudo | Jul 30, 2024 | Mar 5, 2013 |
| Freebsd | — | Upgrade sudo | Dec 10, 2025 | Mar 1, 2013 |
| Gentoo Linux | — | Upgrade app-admin/sudo. | Oct 30, 2017 | Mar 5, 2013 |
| Oracle Solaris | — | Upgrade security/sudo to version 1.8.6.7-0.175.1.7.0.3.0 on Solaris 11.1 | May 29, 2017 | Mar 5, 2013 |
| Oracle_linux | — | Upgrade sudo-develUpgrade sudo | Oct 16, 2024 | Mar 4, 2013 |
| Suse | — | Upgrade sudo-debugsourceUpgrade sudo-debuginfoUpgrade sudo-develUpgrade sudo | Dec 12, 2013 | Mar 5, 2013 |
| Ubuntu | — | Upgrade sudoUpgrade sudo-ldap | Nov 8, 2024 | Mar 5, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub