CVE-2017-1000367: Race Condition
A flaw was found in the way sudo read the device number of the tty from field 7 (ttynr) from "/proc/[pid]/stat". A local attacker could use this flaw to escalate his privilege to root.
Other sources
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the getprocessttyname() function resulting in information disclosure and command execution.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000367?
CVE-2017-1000367 has a high severity rating due to the potential for local privilege escalation to root.
How do I fix CVE-2017-1000367?
To fix CVE-2017-1000367, upgrade to Sudo version 1.8.21 or later.
Who is affected by CVE-2017-1000367?
CVE-2017-1000367 affects systems running Sudo version 1.8.20 and earlier.
What is the attack vector for CVE-2017-1000367?
The attack vector for CVE-2017-1000367 is local, requiring an attacker to have access to the system.
What impact does CVE-2017-1000367 have on a system?
CVE-2017-1000367 can allow unprivileged users to escalate privileges to root, compromising the system's integrity.