PT-2017-2230 · Sudo+5 · Sudo+5

Stephane Chazelas

·

Published

2017-06-02

·

Updated

2024-06-15

·

CVE-2017-1000368

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions sudo versions 1.8.20p1 and earlier
Description The issue is related to insufficient input validation, specifically embedded newlines, in the get process ttyname() function. This can result in information disclosure and command execution. A remote attacker may exploit this to execute arbitrary commands and gain access to information.
Recommendations For sudo versions 1.8.20p1 and earlier, consider restricting access to the get process ttyname() function until a patch is available. As a temporary workaround, limit the execution of commands that utilize this function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1686
BDU:2017-01424
CESA-2017_1574
CVE-2017-1000368
DLA-1011-1
OPENSUSE-SU-2017_1697-1
OPENSUSE-SU-2024:11413-1
RHSA-2017:1574
RHSA-2017_1574
SUSE-SU-2017:1626-1
SUSE-SU-2017:1627-1
SUSE-SU-2017:1771-1
SUSE-SU-2017:1778-1
SUSE-SU-2017_1771-1
SUSE-SU-2017_1778-1
USN-3968-1
USN-3968-2

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Sudo