Description
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.
References (17)
Core 17
Core References
Vendor Advisory vendor-advisory
x_refsource_slackware
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2013&m=slackware-security.517440
Issue Tracking x_refsource_misc
https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/87023
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/62741
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2013/dsa-2642
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/02/27/31
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
Vendor Advisory x_refsource_confirm
http://www.sudo.ws/repos/sudo/rev/049a12a5cc14
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/58207
Issue Tracking x_refsource_misc
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=701839
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1701.html
Vendor Advisory x_refsource_confirm
http://www.sudo.ws/repos/sudo/rev/0c0283d1fafa
Various Sources x_refsource_confirm
http://www.sudo.ws/sudo/alerts/tty_tickets.html
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1353.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT205031
Issue Tracking x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=916365
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/82453
Scores
EPSS
0.0037
EPSS Percentile
29.6%
Details
CWE
CWE-264
Status
published
Products (50)
apple/mac_os_x
< 10.10.4
todd_miller/sudo
1.3.5
todd_miller/sudo
1.6
todd_miller/sudo
1.6.1
todd_miller/sudo
1.6.2
todd_miller/sudo
1.6.2p3
todd_miller/sudo
1.6.3
todd_miller/sudo
1.6.3_p7
todd_miller/sudo
1.6.4
todd_miller/sudo
1.6.4p2
... and 40 more
Published
Apr 08, 2013
Tracked Since
Feb 18, 2026