CVE Vulnerabilities

CVE-2012-0809

Use of Externally-Controlled Format String

Published: Feb 01, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
7.2 LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
LOW

Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

Name Vendor Start Version End Version
Sudo Todd_miller 1.8.0 (including) 1.8.0 (including)
Sudo Todd_miller 1.8.1 (including) 1.8.1 (including)
Sudo Todd_miller 1.8.1p1 (including) 1.8.1p1 (including)
Sudo Todd_miller 1.8.1p2 (including) 1.8.1p2 (including)
Sudo Todd_miller 1.8.2 (including) 1.8.2 (including)
Sudo Todd_miller 1.8.3 (including) 1.8.3 (including)
Sudo Todd_miller 1.8.3p1 (including) 1.8.3p1 (including)
Sudo Ubuntu devel *
Sudo Ubuntu precise *
Sudo Ubuntu upstream *

Potential Mitigations

References