Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-9680

Опубликовано: 24 апр. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1
CVSS3: 3.3

Описание

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

РелизСтатусПримечание
devel

released

1.8.9p5-1ubuntu5
esm-infra-legacy/trusty

released

1.8.9p5-1ubuntu1.1
lucid

released

1.7.2p1-1ubuntu5.8
precise

released

1.8.3p1-1ubuntu3.7
trusty

released

1.8.9p5-1ubuntu1.1
trusty/esm

released

1.8.9p5-1ubuntu1.1
upstream

released

1.7.10p9, 1.8.12
utopic

released

1.8.9p5-1ubuntu2.1

Показывать по

EPSS

Процентиль: 59%
0.00377
Низкий

2.1 Low

CVSS2

3.3 Low

CVSS3

Связанные уязвимости

redhat
около 11 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

CVSS3: 3.3
nvd
больше 8 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

CVSS3: 3.3
debian
больше 8 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is ...

suse-cvrf
около 10 лет назад

Security update for sudo

CVSS3: 3.3
github
больше 3 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

EPSS

Процентиль: 59%
0.00377
Низкий

2.1 Low

CVSS2

3.3 Low

CVSS3