Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2012-0809

Published: 1 February 2012

Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.

Notes

AuthorNote
jdstrand
per upstream, introduced in 1.8, so only 12.04 affected
-D_FORTIFY_SOURCE=2 in combination with ASLR and NX should
adequately protect against this until an update is provided

Priority

Low

Status

Package Release Status
sudo
Launchpad, Ubuntu, Debian
hardy Not vulnerable

lucid Not vulnerable

maverick Not vulnerable

natty Not vulnerable

oneiric Not vulnerable
(1.7.4p6-1ubuntu2)
precise
Released (1.8.3p1-1ubuntu3)
upstream
Released (1.8.3p2)