Back

HIGH

sudo: Multiple netmask values used in Host / Host_List configuration cause any host to be allowed access

Published May 18, 2012

Description

sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 18, 2012
Updated Aug 6, 2024
Reserved Apr 19, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date May 16, 2012