CVE-2012-2337
Publication date 16 May 2012
Last updated 24 July 2024
Ubuntu priority
sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.
Status
Package | Ubuntu Release | Status |
---|---|---|
sudo | ||
Notes
tyhicks
Not easy to reproduce and requires that the user exploiting this flaw to already be specified in the sudoers file
Patch details
Package | Patch details |
---|---|
sudo |
References
Related Ubuntu Security Notices (USN)
- USN-1442-1
- Sudo vulnerability
- 16 May 2012