sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.
CVSS Details
- CVSS 3.0 Base Score: 3.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sudo | Aug 30, 2017 | Apr 24, 2017 |
| Apple Osx Apache | — | Apply OS X security update 2015-006Upgrade macOS to the latest version | Aug 28, 2015 | Aug 28, 2015 |
| Apple Osx Sudo | — | Upgrade macOS to the latest version | Mar 29, 2016 | Mar 29, 2016 |
| Debian | — | Upgrade sudo | Jul 30, 2024 | Apr 24, 2017 |
| Gentoo Linux | — | Upgrade app-admin/sudo. | Oct 30, 2017 | Apr 24, 2017 |
| Oracle_linux | — | Upgrade sudo-develUpgrade sudo | Oct 16, 2024 | Apr 24, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 24, 2017 |
| Suse | — | Upgrade sudoUpgrade sudo-develUpgrade sudo-plugin-python | Dec 18, 2015 | Mar 16, 2015 |
| Ubuntu | — | Upgrade sudo-ldapUpgrade sudo | Nov 8, 2024 | Apr 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub