UBUNTU-CVE-2016-7076
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-7076
UBUNTU-CVE-2016-7076
Summary:
Details: sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.
References: https://ubuntu.com/security/CVE-2016-7076, https://www.sudo.ws/alerts/noexec_wordexp.html, https://ubuntu.com/security/notices/USN-3968-1, https://ubuntu.com/security/notices/USN-3968-3, https://www.cve.org/CVERecord?id=CVE-2016-7076
Affected packages
Package
Name: sudo
Purl: pkg:deb/ubuntu/[email protected]+esm5?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
