Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v56m-9vh5-5qh5

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.

sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.

EPSS

Процентиль: 23%
0.00074
Низкий

7.8 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 6.4
ubuntu
больше 7 лет назад

sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.

CVSS3: 6.4
redhat
около 9 лет назад

sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.

CVSS3: 6.4
nvd
больше 7 лет назад

sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.

CVSS3: 6.4
debian
больше 7 лет назад

sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noe ...

suse-cvrf
почти 9 лет назад

Security update for sudo

EPSS

Процентиль: 23%
0.00074
Низкий

7.8 High

CVSS3

Дефекты

CWE-77