First published: Mon May 22 2017(Updated: )
A flaw was found in the way sudo read the device number of the tty from field 7 (tty_nr) from "/proc/[pid]/stat". A local attacker could use this flaw to escalate his privilege to root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sudo | <=1.8.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000367 has a high severity rating due to the potential for local privilege escalation to root.
To fix CVE-2017-1000367, upgrade to Sudo version 1.8.21 or later.
CVE-2017-1000367 affects systems running Sudo version 1.8.20 and earlier.
The attack vector for CVE-2017-1000367 is local, requiring an attacker to have access to the system.
CVE-2017-1000367 can allow unprivileged users to escalate privileges to root, compromising the system's integrity.