Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-1776

Опубликовано: 08 апр. 2013
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.4

Описание

sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.

РелизСтатусПримечание
devel

ignored

hardy

ignored

lucid

ignored

oneiric

ignored

precise

ignored

quantal

ignored

upstream

released

1.7.10p7, 1.8.6p7

Показывать по

EPSS

Процентиль: 15%
0.0005
Низкий

4.4 Medium

CVSS2

Связанные уязвимости

redhat
больше 12 лет назад

sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.

nvd
больше 12 лет назад

sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.

debian
больше 12 лет назад

sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_ticket ...

github
больше 3 лет назад

sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.

oracle-oval
почти 12 лет назад

ELSA-2013-1353: sudo security and bug fix update (LOW)

EPSS

Процентиль: 15%
0.0005
Низкий

4.4 Medium

CVSS2