CVE-2017-1000368
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
- Sudo Project Sudo
- ≤ 1.8.20
- CVSS 3.0
- 8.2 HIGH
- EPSS
- 0.6% (44th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2017-06-05
CVE-2017-1000368 at NVD
No indexed exploits for CVE-2017-1000368 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2017-1000368 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.