CVE-2016-7032

Published on: 04/14/2017 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:06 PM UTC

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Certain versions of Sudo from Todd Miller contain the following vulnerability:

sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.

  • CVE-2016-7032 has been assigned by [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 7 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
LOCAL HIGH LOW NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH HIGH HIGH

CVSS2 Score: 6.9 - MEDIUM

Access
Vector
Access
Complexity
Authentication
LOCAL MEDIUM NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
COMPLETE COMPLETE COMPLETE

CVE References

Description Tags Link
Potential bypass of sudo_noexec.so on Linux www.sudo.ws
text/html
URL Logo CONFIRM www.sudo.ws/alerts/noexec_bypass.html
USN-3968-3: Sudo vulnerabilities | Ubuntu security notices | Ubuntu usn.ubuntu.com
text/html
URL Logo UBUNTU USN-3968-3
Red Hat Customer Portal web.archive.org
text/html
Inactive LinkNot Archived
URL Logo REDHAT RHSA-2016:2872
IBM PowerKVM CVE-2016-7032 Multiple Local Command Execution Vulnerabilities Third Party Advisory
VDB Entry
cve.report (archive)
text/html
URL Logo BID 95776
1372830 – (CVE-2016-7032) CVE-2016-7032 sudo: noexec bypass via system() and popen() Issue Tracking
Third Party Advisory
VDB Entry
bugzilla.redhat.com
text/html
URL Logo CONFIRM bugzilla.redhat.com/show_bug.cgi?id=1372830

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationTodd MillerSudo1.6.8AllAllAll
ApplicationTodd MillerSudo1.6.9AllAllAll
ApplicationTodd MillerSudo1.7.0AllAllAll
ApplicationTodd MillerSudo1.7.1AllAllAll
ApplicationTodd MillerSudo1.7.10AllAllAll
ApplicationTodd MillerSudo1.7.2AllAllAll
ApplicationTodd MillerSudo1.7.3AllAllAll
ApplicationTodd MillerSudo1.7.4AllAllAll
ApplicationTodd MillerSudo1.7.5AllAllAll
ApplicationTodd MillerSudo1.7.6AllAllAll
ApplicationTodd MillerSudo1.7.7AllAllAll
ApplicationTodd MillerSudo1.7.8AllAllAll
ApplicationTodd MillerSudo1.7.9AllAllAll
ApplicationTodd MillerSudo1.8.0AllAllAll
ApplicationTodd MillerSudo1.8.1AllAllAll
ApplicationTodd MillerSudo1.8.10AllAllAll
ApplicationTodd MillerSudo1.8.11AllAllAll
ApplicationTodd MillerSudo1.8.12AllAllAll
ApplicationTodd MillerSudo1.8.13AllAllAll
ApplicationTodd MillerSudo1.8.14p3AllAll
ApplicationTodd MillerSudo1.8.2AllAllAll
ApplicationTodd MillerSudo1.8.3AllAllAll
ApplicationTodd MillerSudo1.8.4AllAllAll
ApplicationTodd MillerSudo1.8.5AllAllAll
ApplicationTodd MillerSudo1.8.6AllAllAll
ApplicationTodd MillerSudo1.8.7AllAllAll
ApplicationTodd MillerSudo1.8.8AllAllAll
ApplicationTodd MillerSudo1.8.9AllAllAll
ApplicationTodd MillerSudo1.6.8AllAllAll
ApplicationTodd MillerSudo1.6.9AllAllAll
ApplicationTodd MillerSudo1.7.0AllAllAll
ApplicationTodd MillerSudo1.7.1AllAllAll
ApplicationTodd MillerSudo1.7.10AllAllAll
ApplicationTodd MillerSudo1.7.2AllAllAll
ApplicationTodd MillerSudo1.7.3AllAllAll
ApplicationTodd MillerSudo1.7.4AllAllAll
ApplicationTodd MillerSudo1.7.5AllAllAll
ApplicationTodd MillerSudo1.7.6AllAllAll
ApplicationTodd MillerSudo1.7.7AllAllAll
ApplicationTodd MillerSudo1.7.8AllAllAll
ApplicationTodd MillerSudo1.7.9AllAllAll
ApplicationTodd MillerSudo1.8.0AllAllAll
ApplicationTodd MillerSudo1.8.1AllAllAll
ApplicationTodd MillerSudo1.8.10AllAllAll
ApplicationTodd MillerSudo1.8.11AllAllAll
ApplicationTodd MillerSudo1.8.12AllAllAll
ApplicationTodd MillerSudo1.8.13AllAllAll
ApplicationTodd MillerSudo1.8.14p3AllAll
ApplicationTodd MillerSudo1.8.2AllAllAll
ApplicationTodd MillerSudo1.8.3AllAllAll
ApplicationTodd MillerSudo1.8.4AllAllAll
ApplicationTodd MillerSudo1.8.5AllAllAll
ApplicationTodd MillerSudo1.8.6AllAllAll
ApplicationTodd MillerSudo1.8.7AllAllAll
ApplicationTodd MillerSudo1.8.8AllAllAll
ApplicationTodd MillerSudo1.8.9AllAllAll
  • cpe:2.3:a:todd_miller:sudo:1.6.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.6.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.13:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.14:p3:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.6.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.6.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.7.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.13:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.14:p3:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:todd_miller:sudo:1.8.9:*:*:*:*:*:*:*: