Описание
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| sudo | fixed | 1.8.20p1-1.1 | package | |
| sudo | fixed | 1.8.19p1-2.1 | buster | package |
| sudo | fixed | 1.8.19p1-2.1 | stretch | package |
| sudo | fixed | 1.8.10p3-1+deb8u5 | jessie | package |
Примечания
https://www.openwall.com/lists/oss-security/2017/06/02/7
https://www.sudo.ws/repos/sudo/raw-rev/15a46f4007dd
EPSS
Связанные уязвимости
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
EPSS