// For flags

CVE-2013-2777

sudo: bypass of tty_tickets constraints

Severity Score

4.4
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to a session without a controlling terminal device and connecting to the standard input, output, and error file descriptors of another terminal. NOTE: this is one of three closely-related vulnerabilities that were originally assigned CVE-2013-1776, but they have been SPLIT because of different affected versions.

sudo anterior a v1.7.10p5 y v1.8.x anterior a v1.8.6p6, cuando la opción tty_tickets esta habilitada, no valida correctamente el control de dispositivo terminal, que permite a los usuarios locales con permisos de sudo para secuestrar a la autorización de otra terminal a través de vectores relacionados con una sesión sin un dispositivo terminal de control y la conexión a una entrada estándar, salida, y descriptores de error de archivo de otros terminal. NOTA: esta es una de las tres vulnerabilidades estrechamente relacionadas con las que se asignó originalmente a CVE-2013-1776, pero se han dividido debido a las diferentes versiones afectadas.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-04-08 CVE Reserved
  • 2013-04-08 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
<= 10.10.4
Search vendor "Apple" for product "Mac Os X" and version " <= 10.10.4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
<= 1.7.10p4
Search vendor "Todd Miller" for product "Sudo" and version " <= 1.7.10p4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.3.5
Search vendor "Todd Miller" for product "Sudo" and version "1.3.5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6
Search vendor "Todd Miller" for product "Sudo" and version "1.6"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.2p3
Search vendor "Todd Miller" for product "Sudo" and version "1.6.2p3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p7
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p7"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.4
Search vendor "Todd Miller" for product "Sudo" and version "1.6.4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.4p2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.4p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.5
Search vendor "Todd Miller" for product "Sudo" and version "1.6.5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.6
Search vendor "Todd Miller" for product "Sudo" and version "1.6.6"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.7
Search vendor "Todd Miller" for product "Sudo" and version "1.6.7"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.7p5
Search vendor "Todd Miller" for product "Sudo" and version "1.6.7p5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.8
Search vendor "Todd Miller" for product "Sudo" and version "1.6.8"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.8p12
Search vendor "Todd Miller" for product "Sudo" and version "1.6.8p12"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.9
Search vendor "Todd Miller" for product "Sudo" and version "1.6.9"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.9p20
Search vendor "Todd Miller" for product "Sudo" and version "1.6.9p20"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.9p21
Search vendor "Todd Miller" for product "Sudo" and version "1.6.9p21"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.9p22
Search vendor "Todd Miller" for product "Sudo" and version "1.6.9p22"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.9p23
Search vendor "Todd Miller" for product "Sudo" and version "1.6.9p23"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.0
Search vendor "Todd Miller" for product "Sudo" and version "1.7.0"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.1
Search vendor "Todd Miller" for product "Sudo" and version "1.7.1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.2
Search vendor "Todd Miller" for product "Sudo" and version "1.7.2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.2p1
Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.2p2
Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.2p3
Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.2p4
Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.2p5
Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.2p6
Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p6"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.2p7
Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p7"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.3b1
Search vendor "Todd Miller" for product "Sudo" and version "1.7.3b1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.4
Search vendor "Todd Miller" for product "Sudo" and version "1.7.4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.4p1
Search vendor "Todd Miller" for product "Sudo" and version "1.7.4p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.4p2
Search vendor "Todd Miller" for product "Sudo" and version "1.7.4p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.4p3
Search vendor "Todd Miller" for product "Sudo" and version "1.7.4p3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.4p4
Search vendor "Todd Miller" for product "Sudo" and version "1.7.4p4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.4p5
Search vendor "Todd Miller" for product "Sudo" and version "1.7.4p5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.4p6
Search vendor "Todd Miller" for product "Sudo" and version "1.7.4p6"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.5
Search vendor "Todd Miller" for product "Sudo" and version "1.7.5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.6
Search vendor "Todd Miller" for product "Sudo" and version "1.7.6"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.6p1
Search vendor "Todd Miller" for product "Sudo" and version "1.7.6p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.6p2
Search vendor "Todd Miller" for product "Sudo" and version "1.7.6p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.7
Search vendor "Todd Miller" for product "Sudo" and version "1.7.7"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.8
Search vendor "Todd Miller" for product "Sudo" and version "1.7.8"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.8p1
Search vendor "Todd Miller" for product "Sudo" and version "1.7.8p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.8p2
Search vendor "Todd Miller" for product "Sudo" and version "1.7.8p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.9
Search vendor "Todd Miller" for product "Sudo" and version "1.7.9"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.9p1
Search vendor "Todd Miller" for product "Sudo" and version "1.7.9p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.10
Search vendor "Todd Miller" for product "Sudo" and version "1.7.10"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.10p1
Search vendor "Todd Miller" for product "Sudo" and version "1.7.10p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.10p2
Search vendor "Todd Miller" for product "Sudo" and version "1.7.10p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.10p3
Search vendor "Todd Miller" for product "Sudo" and version "1.7.10p3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.0
Search vendor "Todd Miller" for product "Sudo" and version "1.8.0"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.1
Search vendor "Todd Miller" for product "Sudo" and version "1.8.1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.1p1
Search vendor "Todd Miller" for product "Sudo" and version "1.8.1p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.1p2
Search vendor "Todd Miller" for product "Sudo" and version "1.8.1p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.2
Search vendor "Todd Miller" for product "Sudo" and version "1.8.2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.3
Search vendor "Todd Miller" for product "Sudo" and version "1.8.3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.3p1
Search vendor "Todd Miller" for product "Sudo" and version "1.8.3p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.3p2
Search vendor "Todd Miller" for product "Sudo" and version "1.8.3p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.4
Search vendor "Todd Miller" for product "Sudo" and version "1.8.4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.4p1
Search vendor "Todd Miller" for product "Sudo" and version "1.8.4p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.4p2
Search vendor "Todd Miller" for product "Sudo" and version "1.8.4p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.4p3
Search vendor "Todd Miller" for product "Sudo" and version "1.8.4p3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.4p4
Search vendor "Todd Miller" for product "Sudo" and version "1.8.4p4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.4p5
Search vendor "Todd Miller" for product "Sudo" and version "1.8.4p5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.5
Search vendor "Todd Miller" for product "Sudo" and version "1.8.5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.6
Search vendor "Todd Miller" for product "Sudo" and version "1.8.6"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.6p1
Search vendor "Todd Miller" for product "Sudo" and version "1.8.6p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.6p2
Search vendor "Todd Miller" for product "Sudo" and version "1.8.6p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.6p3
Search vendor "Todd Miller" for product "Sudo" and version "1.8.6p3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.6p4
Search vendor "Todd Miller" for product "Sudo" and version "1.8.6p4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.8.6p5
Search vendor "Todd Miller" for product "Sudo" and version "1.8.6p5"
-
Affected