CVE-2012-0809

Severity CVSS v4.0:
Pending analysis
Type:
CWE-134 Format String Vulnerability
Publication date:
01/02/2012
Last modified:
11/04/2025

Description

Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:todd_miller:sudo:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.8.1p1:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.8.1p2:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.8.3p1:*:*:*:*:*:*:*