Sploitus

CVE-2016-7076

No indexed exploits for CVE-2016-7076 yet

sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.

Affected products
Alt Linux, Centos, Red Hat, Suse, Ubuntu, Sudo
Sudo Project Sudo
≤ 1.8.18
Fix
Available
CVSS 3.0
7.8 HIGH
EPSS
0.5% (40th percentile)
Weakness
CWE-77, CWE-184
NVD status
Modified
Published
2018-05-29
CVE-2016-7076 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2016-7076 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2016-7076 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.