CVE-2015-8239
Dashboard / Vulnerabilities / CVE-2015-8239
CVE-2015-8239
Summary:
Details: The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.
References: http://www.openwall.com/lists/oss-security/2015/11/18/22, https://bugzilla.redhat.com/show_bug.cgi?id=1283635, https://www.sudo.ws/repos/sudo/rev/0cd3cc8fa195, https://www.sudo.ws/repos/sudo/rev/24a3d9215c64, https://www.sudo.ws/repos/sudo/rev/397722cdd7ec, http://www.openwall.com/lists/oss-security/2015/11/18/22, https://bugzilla.redhat.com/show_bug.cgi?id=1283635, https://www.sudo.ws/repos/sudo/rev/0cd3cc8fa195, https://www.sudo.ws/repos/sudo/rev/24a3d9215c64, https://www.sudo.ws/repos/sudo/rev/397722cdd7ec, https://bugzilla.redhat.com/show_bug.cgi?id=1283635, https://www.sudo.ws/repos/sudo/rev/0cd3cc8fa195, https://www.sudo.ws/repos/sudo/rev/24a3d9215c64, https://www.sudo.ws/repos/sudo/rev/397722cdd7ec
