FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-2337

This CVE name corresponds to:

Entered Topic
2012-05-16 sudo -- netmask vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-2337
Phase Assigned(20120419)

Description

sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.

References

Source Reference
CONFIRM http://www.sudo.ws/sudo/alerts/netmask.html
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=820677
DEBIAN DSA-2478
FEDORA FEDORA-2012-7998
MANDRIVA MDVSA-2012:079
SECTRACK 1027077
SECUNIA 49219
SECUNIA 49244
SECUNIA 49291