sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.
CVSS Details
- CVSS 3.0 Base Score: 3.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | alpine-linux-upgrade-sudo | Aug 30, 2017 | Apr 24, 2017 |
| Apple Osx Sudo | apple-osx-upgrade-latest | Mar 29, 2016 | Mar 29, 2016 | |
| Debian | debian-upgrade-sudo | Jul 30, 2024 | Apr 24, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-app-admin-sudo | Oct 30, 2017 | Apr 24, 2017 | |
| Oracle_linux | — | oracle-linux-upgrade-sudooracle-linux-upgrade-sudo-devel | Oct 16, 2024 | Apr 24, 2017 |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Apr 24, 2017 | |
| Ubuntu | ubuntu-upgrade-sudoubuntu-upgrade-sudo-ldap | Nov 8, 2024 | Apr 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub