Логотип exploitDog
bind:CVE-2025-32463
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-32463

Количество 6

Количество 6

ubuntu логотип

CVE-2025-32463

17 дней назад

An attacker can leverage sudo's `-R` (`--chroot`) option to run arbitrary commands as root, even if they are not listed in the sudoers file. Sudo versions 1.9.14 to 1.9.17 inclusive are affected.

CVSS3: 9.3
EPSS: Низкий
redhat логотип

CVE-2025-32463

17 дней назад

A flaw was found in Sudo. This flaw allows a local attacker to escalate their privileges by tricking Sudo into loading an arbitrary shared library using the user-specified root directory via the `-R` (`--chroot`) option. An attacker can run arbitrary commands as root on systems that support `/etc/nsswitch.conf`.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2025-32463

17 дней назад

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

CVSS3: 9.3
EPSS: Низкий
debian логотип

CVE-2025-32463

17 дней назад

Sudo before 1.9.17p1 allows local users to obtain root access because ...

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-695j-c63m-mvxc

17 дней назад

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

CVSS3: 9.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02177-1

17 дней назад

Security update for sudo

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-32463

An attacker can leverage sudo's `-R` (`--chroot`) option to run arbitrary commands as root, even if they are not listed in the sudoers file. Sudo versions 1.9.14 to 1.9.17 inclusive are affected.

CVSS3: 9.3
0%
Низкий
17 дней назад
redhat логотип
CVE-2025-32463

A flaw was found in Sudo. This flaw allows a local attacker to escalate their privileges by tricking Sudo into loading an arbitrary shared library using the user-specified root directory via the `-R` (`--chroot`) option. An attacker can run arbitrary commands as root on systems that support `/etc/nsswitch.conf`.

CVSS3: 7.8
0%
Низкий
17 дней назад
nvd логотип
CVE-2025-32463

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

CVSS3: 9.3
0%
Низкий
17 дней назад
debian логотип
CVE-2025-32463

Sudo before 1.9.17p1 allows local users to obtain root access because ...

CVSS3: 9.3
0%
Низкий
17 дней назад
github логотип
GHSA-695j-c63m-mvxc

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

CVSS3: 9.3
0%
Низкий
17 дней назад
suse-cvrf логотип
SUSE-SU-2025:02177-1

Security update for sudo

17 дней назад

Уязвимостей на страницу