First published: Thu Nov 19 2015(Updated: )
A vulnerability in functionality for adding support of SHA-2 digests along with the command was found. The sudoers plugin performs this digest verification while matching rules, and later independently calls execve() to execute the binary. This results in a race condition if the digest functionality is used as suggested (in fact, the rules are matched before the user is prompted for a password, so there is not negligible time frame to replace the binary from underneath sudo). Versions affected are since 1.8.7. CVE assignment: <a href="http://seclists.org/oss-sec/2015/q4/327">http://seclists.org/oss-sec/2015/q4/327</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sudo Project Sudo | =1.8.8 | |
Sudo Project Sudo | =1.8.8-b1 | |
Sudo Project Sudo | =1.8.8-b2 | |
Sudo Project Sudo | =1.8.8-b3 | |
Sudo Project Sudo | =1.8.8-rc1 | |
Sudo Project Sudo | =1.8.9 | |
Sudo Project Sudo | =1.8.9-b1 | |
Sudo Project Sudo | =1.8.9-b2 | |
Sudo Project Sudo | =1.8.9-p1 | |
Sudo Project Sudo | =1.8.9-p2 | |
Sudo Project Sudo | =1.8.9-p3 | |
Sudo Project Sudo | =1.8.9-p4 | |
Sudo Project Sudo | =1.8.9-p5 | |
Sudo Project Sudo | =1.8.9-rc1 | |
Sudo Project Sudo | =1.8.9-rc2 | |
Sudo Project Sudo | =1.8.10 | |
Sudo Project Sudo | =1.8.10-b1 | |
Sudo Project Sudo | =1.8.10-b2 | |
Sudo Project Sudo | =1.8.10-b3 | |
Sudo Project Sudo | =1.8.10-b4 | |
Sudo Project Sudo | =1.8.10-p1 | |
Sudo Project Sudo | =1.8.10-p2 | |
Sudo Project Sudo | =1.8.10-p3 | |
Sudo Project Sudo | =1.8.10-rc1 | |
Sudo Project Sudo | =1.8.10-rc2 | |
Sudo Project Sudo | =1.8.10-rc3 | |
Sudo Project Sudo | =1.8.11 | |
Sudo Project Sudo | =1.8.11-b1 | |
Sudo Project Sudo | =1.8.11-b2 | |
Sudo Project Sudo | =1.8.11-b3 | |
Sudo Project Sudo | =1.8.11-b4 | |
Sudo Project Sudo | =1.8.11-p1 | |
Sudo Project Sudo | =1.8.11-p2 | |
Sudo Project Sudo | =1.8.11-rc1 | |
Sudo Project Sudo | =1.8.11-rc2 | |
Sudo Project Sudo | =1.8.12 | |
Sudo Project Sudo | =1.8.12-b1 | |
Sudo Project Sudo | =1.8.12-b2 | |
Sudo Project Sudo | =1.8.12-b3 | |
Sudo Project Sudo | =1.8.12-rc1 | |
Sudo Project Sudo | =1.8.12-rc2 | |
Sudo Project Sudo | =1.8.13 | |
Sudo Project Sudo | =1.8.13-b1 | |
Sudo Project Sudo | =1.8.13-b2 | |
Sudo Project Sudo | =1.8.13-b3 | |
Sudo Project Sudo | =1.8.13-b4 | |
Sudo Project Sudo | =1.8.13-rc1 | |
Sudo Project Sudo | =1.8.13-rc2 | |
Sudo Project Sudo | =1.8.14 | |
Sudo Project Sudo | =1.8.14-b1 | |
Sudo Project Sudo | =1.8.14-b2 | |
Sudo Project Sudo | =1.8.14-b3 | |
Sudo Project Sudo | =1.8.14-b4 | |
Sudo Project Sudo | =1.8.14-p1 | |
Sudo Project Sudo | =1.8.14-p2 | |
Sudo Project Sudo | =1.8.14-p3 | |
Sudo Project Sudo | =1.8.14-rc1 | |
Sudo Project Sudo | =1.8.15 | |
Sudo Project Sudo | =1.8.15-b1 | |
Sudo Project Sudo | =1.8.15-b2 | |
Sudo Project Sudo | =1.8.15-b3 | |
Sudo Project Sudo | =1.8.15-b4 | |
Sudo Project Sudo | =1.8.15-b5 | |
Sudo Project Sudo | =1.8.15-rc1 | |
Sudo Project Sudo | =1.8.15-rc2 | |
Sudo Project Sudo | =1.8.15-rc3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.