CVE-2013-1776
sudo 1.3.5-1.7.10 and 1.8.0-1.8.5 - Terminal Authorization Hijack via File Descriptor Manipulation
Title source: llmDescription
sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.
References (16)
Core 16
Core References
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/58207
Issue Tracking x_refsource_misc
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=701839
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2013/dsa-2642
Various Sources x_refsource_confirm
http://www.sudo.ws/repos/sudo/rev/6b22be4d09f0
Various Sources x_refsource_confirm
http://www.sudo.ws/repos/sudo/rev/632f8e028191
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/02/27/31
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-03/msg00066.html
Vendor Advisory x_refsource_confirm
http://www.sudo.ws/sudo/alerts/tty_tickets.html
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
Vendor Advisory vendor-advisory
x_refsource_slackware
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2013&m=slackware-security.517440
Issue Tracking x_refsource_misc
https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/87023
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1353.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT205031
Issue Tracking x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=916365
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/82453
Scores
EPSS
0.0037
EPSS Percentile
30.1%
Details
CWE
CWE-264
Status
published
Products (50)
apple/mac_os_x
< 10.10.4
todd_miller/sudo
1.8.0
todd_miller/sudo
1.8.1
todd_miller/sudo
1.8.1p1
todd_miller/sudo
1.8.1p2
todd_miller/sudo
1.8.2
todd_miller/sudo
1.8.3
todd_miller/sudo
1.8.3p1
todd_miller/sudo
1.8.3p2
todd_miller/sudo
1.8.4
... and 40 more
Published
Apr 08, 2013
Tracked Since
Feb 18, 2026