Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-9680

Опубликовано: 24 апр. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1
CVSS3: 3.3

Описание

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

РелизСтатусПримечание
devel

released

1.8.9p5-1ubuntu5
esm-infra-legacy/trusty

released

1.8.9p5-1ubuntu1.1
lucid

released

1.7.2p1-1ubuntu5.8
precise

released

1.8.3p1-1ubuntu3.7
trusty

released

1.8.9p5-1ubuntu1.1
trusty/esm

released

1.8.9p5-1ubuntu1.1
upstream

released

1.7.10p9, 1.8.12
utopic

released

1.8.9p5-1ubuntu2.1

Показывать по

EPSS

Процентиль: 38%
0.0047
Низкий

2.1 Low

CVSS2

3.3 Low

CVSS3

Связанные уязвимости

redhat
почти 12 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

CVSS3: 3.3
nvd
больше 9 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

CVSS3: 3.3
debian
больше 9 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is ...

suse-cvrf
почти 11 лет назад

Security update for sudo

CVSS3: 3.3
github
около 4 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

EPSS

Процентиль: 38%
0.0047
Низкий

2.1 Low

CVSS2

3.3 Low

CVSS3