CVE-2017-1000367
05.06.2017, 14:29
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sudo_project | sudo | 𝑥 ≤ 1.8.20 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sudo |
| ||||||||||||||||||||||||
| sudo-devel |
| ||||||||||||||||||||||||
| sudo-plugin-python |
|
Red Hat Enterprise Linux Releases
References