CVE-2013-2776
sudo: bypass of tty_tickets constraints
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.
sudo v1.3.5 hasta v1.7.10p5 y v1.8.0 hasta v1.8.6p6, cuando se ejecuta en sistemas sin /proc o la función sysctl con la opción tty_tickets habilitada, no valida correctamente el control de dispositivo terminal, lo que permite a los usuarios locales con permisos de sudo para secuestrar a la autorización de otra terminal a través de vectores relacionados con una sesión sin un dispositivo terminal de control y la conexión a una entrada estándar, salida, y descriptores de error de archivo de otros terminal. NOTA: esta es una de las tres vulnerabilidades estrechamente relacionadas con las que se asignó originalmente a CVE-2013-1776, pero se han dividido debido a las diferentes versiones afectadas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-04-08 CVE Reserved
- 2013-04-08 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (19)
URL | Tag | Source |
---|---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=701839 | X_refsource_misc | |
http://www.openwall.com/lists/oss-security/2013/02/27/31 | Mailing List | |
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html | X_refsource_confirm | |
http://www.securityfocus.com/bid/58207 | Vdb Entry | |
http://www.securityfocus.com/bid/62741 | Vdb Entry | |
http://www.sudo.ws/sudo/alerts/tty_tickets.html | X_refsource_confirm | |
https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/87023 | X_refsource_misc | |
https://bugzilla.redhat.com/show_bug.cgi?id=916365 | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/82453 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.3.5 Search vendor "Todd Miller" for product "Sudo" and version "1.3.5" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6 Search vendor "Todd Miller" for product "Sudo" and version "1.6" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.1 Search vendor "Todd Miller" for product "Sudo" and version "1.6.1" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.2 Search vendor "Todd Miller" for product "Sudo" and version "1.6.2" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.2p3 Search vendor "Todd Miller" for product "Sudo" and version "1.6.2p3" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.3 Search vendor "Todd Miller" for product "Sudo" and version "1.6.3" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.3_p7 Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p7" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.4 Search vendor "Todd Miller" for product "Sudo" and version "1.6.4" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.4p2 Search vendor "Todd Miller" for product "Sudo" and version "1.6.4p2" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.5 Search vendor "Todd Miller" for product "Sudo" and version "1.6.5" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.6 Search vendor "Todd Miller" for product "Sudo" and version "1.6.6" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.7 Search vendor "Todd Miller" for product "Sudo" and version "1.6.7" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.7p5 Search vendor "Todd Miller" for product "Sudo" and version "1.6.7p5" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.8 Search vendor "Todd Miller" for product "Sudo" and version "1.6.8" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.8p12 Search vendor "Todd Miller" for product "Sudo" and version "1.6.8p12" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.9 Search vendor "Todd Miller" for product "Sudo" and version "1.6.9" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.9p20 Search vendor "Todd Miller" for product "Sudo" and version "1.6.9p20" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.9p21 Search vendor "Todd Miller" for product "Sudo" and version "1.6.9p21" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.9p22 Search vendor "Todd Miller" for product "Sudo" and version "1.6.9p22" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.6.9p23 Search vendor "Todd Miller" for product "Sudo" and version "1.6.9p23" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.0 Search vendor "Todd Miller" for product "Sudo" and version "1.7.0" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.1 Search vendor "Todd Miller" for product "Sudo" and version "1.7.1" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.2 Search vendor "Todd Miller" for product "Sudo" and version "1.7.2" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.2p1 Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p1" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.2p2 Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p2" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.2p3 Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p3" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.2p4 Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p4" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.2p5 Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p5" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.2p6 Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p6" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.2p7 Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p7" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.3b1 Search vendor "Todd Miller" for product "Sudo" and version "1.7.3b1" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.4 Search vendor "Todd Miller" for product "Sudo" and version "1.7.4" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.4p1 Search vendor "Todd Miller" for product "Sudo" and version "1.7.4p1" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.4p2 Search vendor "Todd Miller" for product "Sudo" and version "1.7.4p2" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.4p3 Search vendor "Todd Miller" for product "Sudo" and version "1.7.4p3" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.4p4 Search vendor "Todd Miller" for product "Sudo" and version "1.7.4p4" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.4p5 Search vendor "Todd Miller" for product "Sudo" and version "1.7.4p5" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.4p6 Search vendor "Todd Miller" for product "Sudo" and version "1.7.4p6" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.5 Search vendor "Todd Miller" for product "Sudo" and version "1.7.5" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.6 Search vendor "Todd Miller" for product "Sudo" and version "1.7.6" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.6p1 Search vendor "Todd Miller" for product "Sudo" and version "1.7.6p1" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.6p2 Search vendor "Todd Miller" for product "Sudo" and version "1.7.6p2" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.7 Search vendor "Todd Miller" for product "Sudo" and version "1.7.7" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.8 Search vendor "Todd Miller" for product "Sudo" and version "1.7.8" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.8p1 Search vendor "Todd Miller" for product "Sudo" and version "1.7.8p1" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.8p2 Search vendor "Todd Miller" for product "Sudo" and version "1.7.8p2" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.9 Search vendor "Todd Miller" for product "Sudo" and version "1.7.9" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.9p1 Search vendor "Todd Miller" for product "Sudo" and version "1.7.9p1" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.10 Search vendor "Todd Miller" for product "Sudo" and version "1.7.10" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.10p1 Search vendor "Todd Miller" for product "Sudo" and version "1.7.10p1" | - |
Safe
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.10p2 Search vendor "Todd Miller" for product "Sudo" and version "1.7.10p2" | - |
Safe
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.10p3 Search vendor "Todd Miller" for product "Sudo" and version "1.7.10p3" | - |
Safe
| ||||||
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | <= 10.10.4 Search vendor "Apple" for product "Mac Os X" and version " <= 10.10.4" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.10p4 Search vendor "Todd Miller" for product "Sudo" and version "1.7.10p4" | - |
Safe
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.7.10p5 Search vendor "Todd Miller" for product "Sudo" and version "1.7.10p5" | - |
Safe
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.0 Search vendor "Todd Miller" for product "Sudo" and version "1.8.0" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.1 Search vendor "Todd Miller" for product "Sudo" and version "1.8.1" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.1p1 Search vendor "Todd Miller" for product "Sudo" and version "1.8.1p1" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.1p2 Search vendor "Todd Miller" for product "Sudo" and version "1.8.1p2" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.2 Search vendor "Todd Miller" for product "Sudo" and version "1.8.2" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.3 Search vendor "Todd Miller" for product "Sudo" and version "1.8.3" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.3p1 Search vendor "Todd Miller" for product "Sudo" and version "1.8.3p1" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.3p2 Search vendor "Todd Miller" for product "Sudo" and version "1.8.3p2" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.4 Search vendor "Todd Miller" for product "Sudo" and version "1.8.4" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.4p1 Search vendor "Todd Miller" for product "Sudo" and version "1.8.4p1" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.4p2 Search vendor "Todd Miller" for product "Sudo" and version "1.8.4p2" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.4p3 Search vendor "Todd Miller" for product "Sudo" and version "1.8.4p3" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.4p4 Search vendor "Todd Miller" for product "Sudo" and version "1.8.4p4" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.4p5 Search vendor "Todd Miller" for product "Sudo" and version "1.8.4p5" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.5 Search vendor "Todd Miller" for product "Sudo" and version "1.8.5" | - |
Affected
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.6 Search vendor "Todd Miller" for product "Sudo" and version "1.8.6" | - |
Safe
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.6p1 Search vendor "Todd Miller" for product "Sudo" and version "1.8.6p1" | - |
Safe
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.6p2 Search vendor "Todd Miller" for product "Sudo" and version "1.8.6p2" | - |
Safe
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.6p3 Search vendor "Todd Miller" for product "Sudo" and version "1.8.6p3" | - |
Safe
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.6p4 Search vendor "Todd Miller" for product "Sudo" and version "1.8.6p4" | - |
Safe
| ||||||
Todd Miller Search vendor "Todd Miller" | Sudo Search vendor "Todd Miller" for product "Sudo" | 1.8.6p5 Search vendor "Todd Miller" for product "Sudo" and version "1.8.6p5" | - |
Safe
|