CVE-2012-2337
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
18/05/2012
Last modified:
11/04/2025
Description
sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.
Impact
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:todd_miller:sudo:1.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.2p3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.3_p7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.4p2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.7p5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.8p12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:todd_miller:sudo:1.6.9:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081432.html
- http://secunia.com/advisories/49219
- http://secunia.com/advisories/49244
- http://secunia.com/advisories/49291
- http://secunia.com/advisories/49948
- http://www.debian.org/security/2012/dsa-2478
- http://www.mandriva.com/security/advisories?name=MDVSA-2012%3A079
- http://www.securitytracker.com/id?1027077=
- http://www.sudo.ws/sudo/alerts/netmask.html
- https://bugzilla.redhat.com/show_bug.cgi?id=820677
- https://www.suse.com/security/cve/CVE-2012-2337/
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081432.html
- http://secunia.com/advisories/49219
- http://secunia.com/advisories/49244
- http://secunia.com/advisories/49291
- http://secunia.com/advisories/49948
- http://www.debian.org/security/2012/dsa-2478
- http://www.mandriva.com/security/advisories?name=MDVSA-2012%3A079
- http://www.securitytracker.com/id?1027077=
- http://www.sudo.ws/sudo/alerts/netmask.html
- https://bugzilla.redhat.com/show_bug.cgi?id=820677
- https://www.suse.com/security/cve/CVE-2012-2337/



