Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7032

Опубликовано: 14 апр. 2017
Источник: debian

Описание

sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sudofixed1.8.15-1package
sudono-dsajessiepackage

Примечания

  • https://www.sudo.ws/alerts/noexec_bypass.html

  • This CVE is for the bypass via system() and popen(). The wordpexp() bypass

  • is tracked under CVE-2016-7076.

  • https://www.sudo.ws/devel.html#1.8.15rc1

  • https://www.sudo.ws/repos/sudo/rev/58a5c06b5257

  • https://www.sudo.ws/repos/sudo/rev/a826cd7787e9

Связанные уязвимости

CVSS3: 7
ubuntu
почти 9 лет назад

sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.

CVSS3: 6.4
redhat
больше 9 лет назад

sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.

CVSS3: 7
nvd
почти 9 лет назад

sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.

CVSS3: 7
github
больше 3 лет назад

sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.

suse-cvrf
около 9 лет назад

Security update for sudo