← Back

Sudo

sudo

Vendor: Sudo Project • 24 CVEs

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sudo Project
1Sudo
May 13, 2026
Jun 5, 2017
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.
1Sudo Project
1Sudo
May 13, 2026
Apr 24, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program w...Show more
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.Show less
1Sudo Project
1Sudo
May 6, 2026
Nov 17, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt."
2Debian
Sudo Project
2Debian Linux
Sudo
Apr 16, 2026
May 16, 2002
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly...Show more
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.Show less