CVE-2017-1000367

Publication date 30 May 2017

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

6.4 · Medium

Score breakdown

Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.

Read the notes from the security team

Status

Package Ubuntu Release Status
sudo 17.04 zesty
Fixed 1.8.19p1-1ubuntu1.1
16.10 yakkety
Fixed 1.8.16-0ubuntu3.2
16.04 LTS xenial
Fixed 1.8.16-0ubuntu1.4
14.04 LTS trusty
Fixed 1.8.9p5-1ubuntu1.4

Notes


sbeattie

code to parse /proc/pid/stat and walk /dev is not present in precise

Severity score breakdown

Parameter Value
Base score 6.4 · Medium
Attack vector Local
Attack complexity High
Privileges required High
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H