UBUNTU-CVE-2014-9680
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-9680
UBUNTU-CVE-2014-9680
Summary:
Details: sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.
References: https://ubuntu.com/security/CVE-2014-9680, http://www.openwall.com/lists/oss-security/2014/10/15/24, http://www.openwall.com/lists/oss-security/2015/02/09/12, http://www.sudo.ws/sudo/alerts/tz.html, https://ubuntu.com/security/notices/USN-2533-1, https://www.cve.org/CVERecord?id=CVE-2014-9680
Affected packages
Package
Name: sudo
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
