Back

HIGH

sudo: format string flaw in sudo_debug()

Published Feb 1, 2012

Description

Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of sudo as shipped with Red Hat Enterprise Linux 4, 5, or 6 as they did not include the vulnerable debugging support.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 1, 2012
Updated Aug 6, 2024
Reserved Jan 19, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jan 30, 2012