VulnerabilityModified
CVE-2015-8239
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.
HIGH 7.0EPSS 0.54%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.
- CVSS 3.0
- 7.0 HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- sudo project/sudo
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2015/11/18/22Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1283635Issue Tracking, Patch, Third Party Advisory
- https://www.sudo.ws/repos/sudo/rev/0cd3cc8fa195Issue Tracking, Patch, Third Party Advisory
- https://www.sudo.ws/repos/sudo/rev/24a3d9215c64Issue Tracking, Patch, Third Party Advisory
- https://www.sudo.ws/repos/sudo/rev/397722cdd7ecIssue Tracking, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/11/18/22Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1283635Issue Tracking, Patch, Third Party Advisory
- https://www.sudo.ws/repos/sudo/rev/0cd3cc8fa195Issue Tracking, Patch, Third Party Advisory
- https://www.sudo.ws/repos/sudo/rev/24a3d9215c64Issue Tracking, Patch, Third Party Advisory
- https://www.sudo.ws/repos/sudo/rev/397722cdd7ecIssue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.