Information on source package sudo

Available versions

ReleaseVersion
jessie1.8.10p3-1+deb8u9
stretch1.8.19p1-2.1+deb9u6
stretch (security)1.8.19p1-2.1+deb9u3
buster1.8.27-1+deb10u6
bullseye1.9.5p2-3+deb11u1
bookworm1.9.13p3-1+deb12u1
trixie1.9.16p1-1
sid1.9.16p1-1

Open issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2023-42465fixedfixedvulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)fixedfixedSudo before 1.9.15 might allow row hammer attacks (for authentication ...
CVE-2023-28487vulnerable (no DSA)fixedfixedvulnerable (no DSA)fixedfixedfixedSudo before 1.9.13 does not escape control characters in sudoreplay ou ...
CVE-2023-28486vulnerable (no DSA)fixedfixedvulnerable (no DSA)fixedfixedfixedSudo before 1.9.13 does not escape control characters in log messages.
CVE-2021-23239vulnerable (no DSA)fixedfixedfixedfixedfixedfixedThe sudoedit personality of Sudo before 1.9.5 may allow a local unpriv ...
CVE-2016-7076vulnerable (no DSA)fixedfixedfixedfixedfixedfixedsudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noe ...
CVE-2016-7032vulnerable (no DSA)fixedfixedfixedfixedfixedfixedsudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users ...
CVE-2015-8239vulnerable (no DSA)fixedfixedfixedfixedfixedfixedThe SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 all ...

Open unimportant issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2022-43995vulnerablevulnerablevulnerablevulnerablefixedfixedfixedSudo 1.8.0 through 1.9.12, with the crypt() password backend, contains ...
CVE-2021-23240vulnerablevulnerablevulnerablefixedfixedfixedfixedselinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a loc ...
CVE-2019-19234vulnerablevulnerablevulnerablefixedfixedfixedfixedIn Sudo through 1.8.29, the fact that a user has been blocked (e.g., b ...
CVE-2019-19232vulnerablevulnerablevulnerablefixedfixedfixedfixedIn Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer ...
CVE-2005-1119vulnerablevulnerablevulnerablevulnerablevulnerablevulnerablevulnerableSudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary ...

Resolved issues

BugDescription
CVE-2023-27320Sudo before 1.9.13p2 has a double free in the per-command chroot featu ...
CVE-2023-22809In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extr ...
CVE-2023-7090A flaw was found in sudo in the handling of ipa_hostname, where ipa_ho ...
CVE-2021-3156Sudo before 1.9.5p2 contains an off-by-one error that can result in a ...
CVE-2019-18634In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users ...
CVE-2019-14287In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer a ...
CVE-2017-1000368Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an in ...
CVE-2017-1000367Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an inpu ...
CVE-2016-7091sudo: It was discovered that the default sudo configuration on Red Hat ...
CVE-2015-5602sudoedit in Sudo before 1.8.15 allows local users to gain privileges v ...
CVE-2014-9680sudo before 1.8.12 does not ensure that the TZ environment variable is ...
CVE-2014-0106Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly ...
CVE-2013-2777sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets op ...
CVE-2013-2776sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on ...
CVE-2013-1776sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_ticket ...
CVE-2013-1775sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows loca ...
CVE-2012-3440A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (R ...
CVE-2012-2337sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does no ...
CVE-2012-0809Format string vulnerability in the sudo_debug function in Sudo 1.8.0 t ...
CVE-2011-0010check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured ...
CVE-2011-0008A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fe ...
CVE-2010-2956Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not ...
CVE-2010-1646The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1. ...
CVE-2010-1163The command matching functionality in sudo 1.6.8 through 1.7.2p5 does ...
CVE-2010-0427sudo 1.6.x before 1.6.9p21, when the runas_default option is used, doe ...
CVE-2010-0426sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-com ...
CVE-2009-0034parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret ...
CVE-2008-3067sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when passwo ...
CVE-2007-3149sudo, when linked with MIT Kerberos 5 (krb5), does not properly check ...
CVE-2006-0151sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environ ...
CVE-2005-4890There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo ...
CVE-2005-4158Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear ...
CVE-2005-2959Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows lo ...
CVE-2005-1993Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-comman ...
CVE-2005-1831Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions ...
CVE-2004-1689sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root ...
CVE-2004-1051sudo before 1.6.8p2 allows local users to execute arbitrary commands b ...

Security announcements

DSA / DLADescription
DLA-3732-1sudo - security update
ELA-1042-1sudo - security update
DSA-5321-1sudo - security update
DLA-3272-1sudo - security update
ELA-772-1sudo - security update
ELA-728-1sudo - security update
DLA-3181-1sudo - security update
ELA-351-1sudo - security update
DSA-4839-1sudo - security update
DLA-2534-1sudo - security update
ELA-213-1sudo - security update
DSA-4614-1sudo - security update
DLA-2094-1sudo - security update
DLA-1964-1sudo - security update
ELA-178-1sudo - security update
DSA-4543-1sudo - security update
DLA-1011-1sudo - security update
DSA-3867-1sudo - security update
DLA-970-1sudo - security update
DLA-707-1sudo - security update
DSA-3440-1sudo - security update
DLA-382-1sudo - security update
DLA-160-1sudo - security update
DSA-3167-1sudo - security update
DSA-2642-1sudo - several issues
DSA-2478-1sudo - parsing error
DSA-2062-1sudo - environment sanitization bypass
DSA-2006-1sudo - several vulnerabilities
DSA-946-2sudo - missing input sanitising
DSA-870-1sudo - missing input sanitising
DSA-735-2sudo - pathname validation race
DSA-735-1sudo - pathname validation race
DSA-596-2sudo - missing input sanitising

Search for package or bug name: Reporting problems