GratiSoft Sudo Restricted Command Execution Bypass Vulnerability
BID:11668
Info
GratiSoft Sudo Restricted Command Execution Bypass Vulnerability
| Bugtraq ID: | 11668 |
| Class: | Design Error |
| CVE: |
CVE-2004-1051 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 12 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Discovery of this issue is credited to Liam Helmer. |
| Vulnerable: |
Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Home Trustix Secure Linux 2.2 Trustix Secure Linux 2.1 Trustix Secure Linux 2.0 Trustix Secure Linux 1.5 Trustix Secure Enterprise Linux 2.0 Todd Miller Sudo 1.6.8 p1 Todd Miller Sudo 1.6.8 Todd Miller Sudo 1.6.7 Todd Miller Sudo 1.6.6 Todd Miller Sudo 1.6.5 p2 Todd Miller Sudo 1.6.5 p1 Todd Miller Sudo 1.6.5 Todd Miller Sudo 1.6.4 p2 Todd Miller Sudo 1.6.4 p1 Todd Miller Sudo 1.6.4 Todd Miller Sudo 1.6.3 p7 Todd Miller Sudo 1.6.3 p6 Todd Miller Sudo 1.6.3 p5 Todd Miller Sudo 1.6.3 p4 Todd Miller Sudo 1.6.3 p3 Todd Miller Sudo 1.6.3 p2 Todd Miller Sudo 1.6.3 p1 Todd Miller Sudo 1.6.3 Todd Miller Sudo 1.6.2 Todd Miller Sudo 1.6.1 Todd Miller Sudo 1.6 Todd Miller Sudo 1.5.9 Todd Miller Sudo 1.5.8 Todd Miller Sudo 1.5.7 Todd Miller Sudo 1.5.6 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core1 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 Mandriva Linux Mandrake 9.2 amd64 Mandriva Linux Mandrake 9.2 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha |
| Not Vulnerable: |
GratiSoft Sudo 1.6.8 p2 |
Discussion
GratiSoft Sudo Restricted Command Execution Bypass Vulnerability
A restricted command execution bypass vulnerability affects GratiSoft's Sudo application. This issue is due to a design error that causes the application to fail to properly sanitize user-supplied environment variables.
An attacker with sudo privileges may leverage this issue to execute commands that are explicitly disallowed. This may facilitate privileges escalation and certainly leads to a false sense of security.
A restricted command execution bypass vulnerability affects GratiSoft's Sudo application. This issue is due to a design error that causes the application to fail to properly sanitize user-supplied environment variables.
An attacker with sudo privileges may leverage this issue to execute commands that are explicitly disallowed. This may facilitate privileges escalation and certainly leads to a false sense of security.
Exploit / POC
GratiSoft Sudo Restricted Command Execution Bypass Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
GratiSoft Sudo Restricted Command Execution Bypass Vulnerability
Solution:
The vendor has released patch level 2 dealing with this issue for Sudo version 1.6.8.
Debian has released an advisory (DSA 596-1) and fixes to address this vulnerability in Debian platforms. Customers are advised to peruse the referenced advisory for further information pertaining to obtaining and applying appropriate fixes
Ubuntu has released an advisory (USN-28-1) and fixes to address this vulnerability in Ubuntu products. Customers are advised to peruse the referenced advisory for further information pertaining to obtaining and applying appropriate fixes.
Mandrake Linux has released an advisory (MDKSA-2004:133) along with fixes dealing with this issue. Please see the referenced advisory for more information.
Trustix Linux has released an advisory (TSLSA-2004-0061) along with updated fixes dealing with this and other issues. Please see the referenced advisory for more information.
OpenPKG has made an advisory (OpenPKG-SA-2005.002) available dealing with this issue. Please see the referenced advisory for more information.
Turbolinux has released advisory Turbolinux Security Announcement 31/Jan/2005 to address various issues. Please see the referenced advisory for more information.
The Fedora Legacy project has released advisory FLSA:152856 to address this issue in RedHat Linux 7.3, 9, and Fedora Core 1. Please see the referenced advisory for further information.
Todd Miller Sudo 1.5.6
Todd Miller Sudo 1.5.7
Todd Miller Sudo 1.5.8
Todd Miller Sudo 1.5.9
Todd Miller Sudo 1.6
Todd Miller Sudo 1.6.1
Todd Miller Sudo 1.6.2
Todd Miller Sudo 1.6.3
Todd Miller Sudo 1.6.3 p1
Todd Miller Sudo 1.6.3 p5
Todd Miller Sudo 1.6.3 p4
Todd Miller Sudo 1.6.3 p7
Todd Miller Sudo 1.6.3 p6
Todd Miller Sudo 1.6.3 p2
Todd Miller Sudo 1.6.3 p3
Todd Miller Sudo 1.6.4 p2
Todd Miller Sudo 1.6.4 p1
Todd Miller Sudo 1.6.4
Todd Miller Sudo 1.6.5 p2
Todd Miller Sudo 1.6.5 p1
Todd Miller Sudo 1.6.5
Todd Miller Sudo 1.6.6
Todd Miller Sudo 1.6.7
Todd Miller Sudo 1.6.8
Todd Miller Sudo 1.6.8 p1
Ubuntu Ubuntu Linux 4.1 ia32
Ubuntu Ubuntu Linux 4.1 ia64
Ubuntu Ubuntu Linux 4.1 ppc
Solution:
The vendor has released patch level 2 dealing with this issue for Sudo version 1.6.8.
Debian has released an advisory (DSA 596-1) and fixes to address this vulnerability in Debian platforms. Customers are advised to peruse the referenced advisory for further information pertaining to obtaining and applying appropriate fixes
Ubuntu has released an advisory (USN-28-1) and fixes to address this vulnerability in Ubuntu products. Customers are advised to peruse the referenced advisory for further information pertaining to obtaining and applying appropriate fixes.
Mandrake Linux has released an advisory (MDKSA-2004:133) along with fixes dealing with this issue. Please see the referenced advisory for more information.
Trustix Linux has released an advisory (TSLSA-2004-0061) along with updated fixes dealing with this and other issues. Please see the referenced advisory for more information.
OpenPKG has made an advisory (OpenPKG-SA-2005.002) available dealing with this issue. Please see the referenced advisory for more information.
Turbolinux has released advisory Turbolinux Security Announcement 31/Jan/2005 to address various issues. Please see the referenced advisory for more information.
The Fedora Legacy project has released advisory FLSA:152856 to address this issue in RedHat Linux 7.3, 9, and Fedora Core 1. Please see the referenced advisory for further information.
Todd Miller Sudo 1.5.6
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.5.7
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.5.8
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.5.9
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.1
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.2
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.3
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.3 p1
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.3 p5
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.3 p4
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.3 p7
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.3 p6
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.3 p2
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.3 p3
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.4 p2
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.4 p1
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.4
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html -
Mandrake sudo-1.6.4-3.2.M82mdk.i586.rpm
Mandrake Multi Network Firewall 8.2
http://www.mandrakesecure.net/en/ftp.php
Todd Miller Sudo 1.6.5 p2
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html -
RedHat sudo-1.6.5p2-2.2.legacy.i386.rpm
RedHat Linux 7.3
http://download.fedoralegacy.org/redhat/7.3/updates/i386/sudo-1.6.5p2- 2.2.legacy.i386.rpm
Todd Miller Sudo 1.6.5 p1
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.5
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.6
-
Debian sudo_1.6.6-1.2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.6-1.2_alp ha.deb -
Debian sudo_1.6.6-1.2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.6-1.2_arm .deb -
Debian sudo_1.6.6-1.2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.6-1.2_hpp a.deb -
Debian sudo_1.6.6-1.2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.6-1.2_i38 6.deb -
Debian sudo_1.6.6-1.2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.6-1.2_ia6 4.deb -
Debian sudo_1.6.6-1.2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.6-1.2_m68 k.deb -
Debian sudo_1.6.6-1.2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.6-1.2_mip s.deb -
Debian sudo_1.6.6-1.2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.6-1.2_mip sel.deb -
Debian sudo_1.6.6-1.2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.6-1.2_pow erpc.deb -
Debian sudo_1.6.6-1.2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.6-1.2_s39 0.deb -
Debian sudo_1.6.6-1.2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sudo/sudo_1.6.6-1.2_spa rc.deb -
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html -
Mandrake sudo-1.6.6-2.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sudo-1.6.6-2.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
RedHat sudo-1.6.6-3.2.legacy.i386.rpm
RedHat Linux 9.0
http://download.fedoralegacy.org/redhat/9/updates/i386/sudo-1.6.6-3.2. legacy.i386.rpm -
Trustix sudo-1.6.8p2-0.1tr.i586.rpm
Trustix Secure Linux 2.0 & 1.5
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix sudo-1.6.8p3-0.1tr.i586.rpm
Trustix Secure Linux 1.5
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix sudo-1.6.8p3-0.1tr.i586.rpm
Trustix Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
TurboLinux sudo-1.6.6-5.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/sudo-1.6.6-5.i586.rpm -
TurboLinux sudo-1.6.6-5.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/8/upd ates/RPMS/sudo-1.6.6-5.i586.rpm -
TurboLinux sudo-1.6.6-5.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/sudo-1.6.6-5.i586.rpm -
TurboLinux sudo-1.6.6-5.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/sudo-1.6.6-5.i586.rpm
Todd Miller Sudo 1.6.7
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html -
Mandrake sudo-1.6.7-0.p5.1.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sudo-1.6.7-0.p5.1.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sudo-1.6.7-0.p5.2.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sudo-1.6.7-0.p5.2.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Trustix sudo-1.6.8p2-0.2tr.i586.rpm
Trustix Secure Linux 2.1
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix sudo-1.6.8p3-0.2tr.i586.rpm
Trustix Secure Linux 2.1
ftp://ftp.trustix.org/pub/trustix/updates/
Todd Miller Sudo 1.6.8
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html
Todd Miller Sudo 1.6.8 p1
-
GratiSoft Sudo 1.6.8p2
http://www.courtesan.com/sudo/download.html -
Mandrake sudo-1.6.8p1-1.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake sudo-1.6.8p1-1.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/X86_64
http://www.mandrakesecure.net/en/ftp.php -
OpenPKG sudo-1.6.8p1-2.2.2.src.rpm
ftp://ftp.openpkg.org/release/2.2/UPD/sudo-1.6.8p1-2.2.2.src.rpm -
Trustix sudo-1.6.8p2-1tr.i586.rpm
Trustix Secure Linux 2.2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix sudo-1.6.8p3-1tr.i586.rpm
Trustix Secure Linux 2.2
ftp://ftp.trustix.org/pub/trustix/updates/
Ubuntu Ubuntu Linux 4.1 ia32
-
Ubuntu sudo_1.6.7p5-1ubuntu4.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.7p5-1ubunt u4.1_i386.deb
Ubuntu Ubuntu Linux 4.1 ia64
-
Ubuntu sudo_1.6.7p5-1ubuntu4.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.7p5-1ubunt u4.1_amd64.deb
Ubuntu Ubuntu Linux 4.1 ppc
-
Ubuntu sudo_1.6.7p5-1ubuntu4.1_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/s/sudo/sudo_1.6.7p5-1ubunt u4.1_powerpc.deb
References
GratiSoft Sudo Restricted Command Execution Bypass Vulnerability
References:
References:
- Bash scripts run via Sudo can be subverted (GratiSoft)
- Sudo Home Page (GratiSoft)