Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-1000367
Description:Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.
Test IDs: 1.3.6.1.4.1.25623.1.0.871826   1.3.6.1.4.1.25623.1.0.851561   1.3.6.1.4.1.25623.1.1.4.2017.1450.1   1.3.6.1.4.1.25623.1.0.871835   1.3.6.1.4.1.25623.1.0.882741   1.3.6.1.4.1.25623.1.0.872731   1.3.6.1.4.1.25623.1.1.2.2017.1121   1.3.6.1.4.1.25623.1.1.2.2017.1106   1.3.6.1.4.1.25623.1.0.882729   1.3.6.1.4.1.25623.1.1.13.2017.150.01   1.3.6.1.4.1.25623.1.0.843187   1.3.6.1.4.1.25623.1.1.2.2017.1120   1.3.6.1.4.1.25623.1.1.10.2017.0207   1.3.6.1.4.1.25623.1.0.872740   1.3.6.1.4.1.25623.1.0.882743   1.3.6.1.4.1.25623.1.1.4.2017.1446.1   1.3.6.1.4.1.25623.1.1.2.2017.1107   1.3.6.1.4.1.25623.1.1.2.2019.1449   1.3.6.1.4.1.25623.1.0.882727   1.3.6.1.4.1.25623.1.1.1.2.2017.970   1.3.6.1.4.1.25623.1.0.703867  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-1000367
BugTraq ID: 98745
http://www.securityfocus.com/bid/98745
Debian Security Information: DSA-3867 (Google Search)
http://www.debian.org/security/2017/dsa-3867
https://www.exploit-db.com/exploits/42183/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VXEXC4NNIG2QOZY6N2YUK246KI3D3UQO/
http://seclists.org/fulldisclosure/2017/Jun/3
https://security.gentoo.org/glsa/201705-15
http://packetstormsecurity.com/files/142783/Sudo-get_process_ttyname-Race-Condition.html
http://www.openwall.com/lists/oss-security/2017/05/30/16
http://www.openwall.com/lists/oss-security/2022/12/22/5
http://www.openwall.com/lists/oss-security/2022/12/22/6
RedHat Security Advisories: RHSA-2017:1381
https://access.redhat.com/errata/RHSA-2017:1381
RedHat Security Advisories: RHSA-2017:1382
https://access.redhat.com/errata/RHSA-2017:1382
http://www.securitytracker.com/id/1038582
SuSE Security Announcement: SUSE-SU-2017:1446 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2017-05/msg00077.html
SuSE Security Announcement: SUSE-SU-2017:1450 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2017-05/msg00078.html
SuSE Security Announcement: openSUSE-SU-2017:1455 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2017-05/msg00079.html
http://www.ubuntu.com/usn/USN-3304-1




© 1998-2025 E-Soft Inc. All rights reserved.