CVE-2019-14287
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 63.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 63.76% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-755
- Affected
- sudo project/sudo · fedoraproject/fedora · debian/debian linux · opensuse/leap · canonical/ubuntu linux · netapp/element software management node · redhat/openshift container platform · redhat/virtualization · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00042.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00047.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/154853/Slackware-Security-Advisory-sudo-Updates.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/10/14/1Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/24/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/29/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/09/14/2Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHBA-2019:3248Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3197Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3204Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3205Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3209Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3219Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3278Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3694Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3754Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3755Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3895Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3916Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3941Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4191Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0388Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00022.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IP7SIOAVLSKJGMTIULX52VQUPTVSC43U/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPLAM57TPJQGKQMNG6RHFBLACD6K356N/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TUVAOZBYUHZS56A5FQSCDVGXT7PW7FL2/
- https://resources.whitesourcesoftware.com/blog-whitesource/new-vulnerability-in-sudo-cve-2019-14287Third Party Advisory
- https://seclists.org/bugtraq/2019/Oct/20Issue Tracking, Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Oct/21Issue Tracking, Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202003-12Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.