sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.
CVSS Details
- CVSS 3.1 Base Score: 6.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade sudo | Jan 5, 2017 | Oct 28, 2016 |
| Centos_linux | — | Upgrade sudo-develUpgrade sudo | Jan 27, 2017 | Oct 28, 2016 |
| Debian | — | Upgrade sudo | Mar 31, 2017 | Oct 28, 2016 |
| Freebsd | — | Upgrade sudo | Nov 14, 2016 | Oct 28, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade sudo | Nov 30, 2017 | Oct 26, 2016 |
| Oracle Solaris | — | Upgrade security/sudo to version 1.8.18.1-0.175.3.15.0.4.0 on Solaris 11.3 | May 29, 2017 | May 29, 2017 |
| Oracle_linux | — | Upgrade sudo-develUpgrade sudo | Dec 6, 2016 | Oct 26, 2016 |
| Redhat_linux | — | No solution existsUpgrade sudoUpgrade sudo-debuginfoUpgrade sudo-devel | Dec 9, 2016 | Oct 28, 2016 |
| Suse | — | Upgrade sudo-develUpgrade sudoUpgrade sudo-plugin-python | Nov 23, 2016 | Oct 28, 2016 |
| Ubuntu | — | Upgrade sudo (Ubuntu Pro)Upgrade sudoUpgrade sudo-ldapUpgrade sudo-ldap (Ubuntu Pro) | May 7, 2019 | Oct 28, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub