Логотип exploitDog
bind:CVE-2019-19232
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-19232

Количество 7

Количество 7

ubuntu логотип

CVE-2019-19232

около 6 лет назад

In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional feature. Because this behavior surprised some users, sudo 1.8.30 introduced an option to enable/disable this behavior with the default being disabled. However, this does not change the fact that sudo was behaving as intended, and as documented, in earlier versions

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2019-19232

около 6 лет назад

In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional feature. Because this behavior surprised some users, sudo 1.8.30 introduced an option to enable/disable this behavior with the default being disabled. However, this does not change the fact that sudo was behaving as intended, and as documented, in earlier versions

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-19232

около 6 лет назад

In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional feature. Because this behavior surprised some users, sudo 1.8.30 introduced an option to enable/disable this behavior with the default being disabled. However, this does not change the fact that sudo was behaving as intended, and as documented, in earlier versions

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-19232

около 6 лет назад

In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g292-5fg6-fchh

больше 3 лет назад

In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2020-1804

почти 6 лет назад

ELSA-2020-1804: sudo security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2020-00857

около 6 лет назад

Уязвимость учетной записи sudoer в файле Runas ALL программы системного администрирования Sudo, позволяющая нарушителю выдать себя за несуществующего пользователя

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-19232

In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional feature. Because this behavior surprised some users, sudo 1.8.30 introduced an option to enable/disable this behavior with the default being disabled. However, this does not change the fact that sudo was behaving as intended, and as documented, in earlier versions

CVSS3: 7.5
3%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-19232

In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional feature. Because this behavior surprised some users, sudo 1.8.30 introduced an option to enable/disable this behavior with the default being disabled. However, this does not change the fact that sudo was behaving as intended, and as documented, in earlier versions

CVSS3: 7.5
3%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-19232

In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional feature. Because this behavior surprised some users, sudo 1.8.30 introduced an option to enable/disable this behavior with the default being disabled. However, this does not change the fact that sudo was behaving as intended, and as documented, in earlier versions

CVSS3: 7.5
3%
Низкий
около 6 лет назад
debian логотип
CVE-2019-19232

In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer ...

CVSS3: 7.5
3%
Низкий
около 6 лет назад
github логотип
GHSA-g292-5fg6-fchh

In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2020-1804

ELSA-2020-1804: sudo security, bug fix, and enhancement update (MODERATE)

почти 6 лет назад
fstec логотип
BDU:2020-00857

Уязвимость учетной записи sudoer в файле Runas ALL программы системного администрирования Sudo, позволяющая нарушителю выдать себя за несуществующего пользователя

CVSS3: 7.5
3%
Низкий
около 6 лет назад

Уязвимостей на страницу