CVE-2017-1000367
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.
- Sudo Project Sudo
- ≤ 1.8.20
- CVSS 2.0
- 6.9 MEDIUM
- CVSS 3.1
- 6.4 MEDIUM
- EPSS
- 8.0% (94th percentile)
- Weakness
- CWE-362
- NVD status
- Modified
- Published
- 2017-06-05
CVE-2017-1000367 at NVD
8 known exploits for CVE-2017-1000367
Proof-of-concept code and exploit modules indexed by Sploitus
Kernelpop - Kernel Privilege Escalation Enumeration And Exploitation Framework
Sudo - get_process_ttyname() Privilege Escalation Vulnerability
Sudo 1.8.20 - get_process_ttyname() Local Privilege Escalation
Sudo 1.8.20 - 'get_process_ttyname()' Local Privilege Escalation
Sudo get_process_ttyname() Race Condition Vulnerability
Sudo get_process_ttyname() Race Condition
Exploit for Race Condition in Sudo_Project Sudo
CVE-2017-1000367 in Sudo's get_process_ttyname() for Linux