Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12518
HistoryJan 15, 2019 - 9:18 a.m.

Arbitrary Command Execution

2019-01-1509:18:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.001 Low

EPSS

Percentile

28.7%

sudo is vulnerable to arbitrary command execution attacks. The vulnerability exists as Todd Miller’s sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.