Sudo Project
sudo_project
24 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation. |
6Canonical DebianOpensuse+3 more8Debian Linux Enterprise LinuxLeap+5 moreJun 17, 2026 Jun 30, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines. |
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client...Show more |
Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and...Show more |
2Netapp Sudo Project2Active Iq Unified Manager SudoJun 17, 2026 Mar 16, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Sudo before 1.9.13 does not escape control characters in sudoreplay output. |
2Netapp Sudo Project2Active Iq Unified Manager SudoJun 17, 2026 Mar 16, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Sudo before 1.9.13 does not escape control characters in log messages. |
2Fedoraproject Sudo Project2Fedora SudoJun 17, 2026 Feb 28, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Sudo before 1.9.13p2 has a double free in the per-command chroot feature. |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Jan 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries...Show more |
Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local...Show more |
8Beyondtrust DebianFedoraproject+5 more24Active Iq Unified Manager Cloud BackupCommunications Performance Intelligence Center+21 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash...Show more |
3Fedoraproject NetappSudo Project4Fedora Hci Management NodeSolidfire+1 moreJun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This aff...Show more |
4Debian FedoraprojectNetapp+1 more6Cloud Backup Debian LinuxFedora+3 moreJun 17, 2026 Jan 12, 2021 N/A· v4 2.5 LOW· v3 1.9 LOW· v2 The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symli...Show more |
2Debian Sudo Project2Debian Linux SudoJun 17, 2026 Jan 29, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however,...Show more |
3Debian RedhatSudo Project4Debian Linux Enterprise LinuxShadow+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into...Show more |
Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process. This occurs because of a race condition between determining a uid, and the setresuid and open...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Element Software Management NodeEnterprise Linux+12 moreJun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For exa...Show more |
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such ap...Show more |
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed. |
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution. |