Lucene search

K
redhatcveRedhat.comRH:CVE-2016-7076
HistoryOct 27, 2016 - 7:47 p.m.

CVE-2016-7076

2016-10-2719:47:35
redhat.com
access.redhat.com
11

EPSS

0

Percentile

5.1%

It was discovered that the sudo noexec restriction could have been bypassed if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.