In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a sudo -u #$((0xffffffff)) command.
The product does not handle or incorrectly handles an exceptional condition.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sudo | Sudo_project | * | 1.8.28 (excluding) |
Red Hat Enterprise Linux 5 Extended Lifecycle Support | RedHat | sudo-0:1.7.2p1-31.el5_11.1 | * |
Red Hat Enterprise Linux 6 | RedHat | sudo-0:1.8.6p3-29.el6_10.2 | * |
Red Hat Enterprise Linux 6.5 Advanced Update Support | RedHat | sudo-0:1.8.6p3-12.el6_5.2 | * |
Red Hat Enterprise Linux 6.6 Advanced Update Support | RedHat | sudo-0:1.8.6p3-15.el6_6.2 | * |
Red Hat Enterprise Linux 7 | RedHat | sudo-0:1.8.23-4.el7_7.1 | * |
Red Hat Enterprise Linux 7.2 Advanced Update Support | RedHat | sudo-0:1.8.6p7-17.el7_2.2 | * |
Red Hat Enterprise Linux 7.2 Telco Extended Update Support | RedHat | sudo-0:1.8.6p7-17.el7_2.2 | * |
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | RedHat | sudo-0:1.8.6p7-17.el7_2.2 | * |
Red Hat Enterprise Linux 7.3 Advanced Update Support | RedHat | sudo-0:1.8.6p7-23.el7_3.2 | * |
Red Hat Enterprise Linux 7.3 Telco Extended Update Support | RedHat | sudo-0:1.8.6p7-23.el7_3.2 | * |
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions | RedHat | sudo-0:1.8.6p7-23.el7_3.2 | * |
Red Hat Enterprise Linux 7.4 Advanced Update Support | RedHat | sudo-0:1.8.19p2-12.el7_4.1 | * |
Red Hat Enterprise Linux 7.4 Telco Extended Update Support | RedHat | sudo-0:1.8.19p2-12.el7_4.1 | * |
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | RedHat | sudo-0:1.8.19p2-12.el7_4.1 | * |
Red Hat Enterprise Linux 7.5 Extended Update Support | RedHat | sudo-0:1.8.19p2-14.el7_5.1 | * |
Red Hat Enterprise Linux 7.6 Extended Update Support | RedHat | sudo-0:1.8.23-3.el7_6.1 | * |
Red Hat Enterprise Linux 8 | RedHat | sudo-0:1.8.25p1-8.el8_1 | * |
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | RedHat | sudo-0:1.8.25p1-4.el8_0.2 | * |
Red Hat OpenShift Container Platform 4 | RedHat | machine-os-content-container | * |
Red Hat OpenShift Container Platform 4 | RedHat | machine-os-content-container | * |
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | RedHat | redhat-release-virtualization-host-0:4.2-15.1.el7 | * |
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | RedHat | redhat-virtualization-host-0:4.2-20191022.0.el7_6 | * |
Sudo | Ubuntu | bionic | * |
Sudo | Ubuntu | devel | * |
Sudo | Ubuntu | disco | * |
Sudo | Ubuntu | trusty | * |
Sudo | Ubuntu | trusty/esm | * |
Sudo | Ubuntu | upstream | * |
Sudo | Ubuntu | xenial | * |