CVE-2012-0809

Priority
Low
Description
Format string vulnerability in the sudo_debug function in Sudo 1.8.0
through 1.8.3p1 allows local users to execute arbitrary code via format
string sequences in the program name for sudo.
References
Notes
 jdstrand> per upstream, introduced in 1.8, so only 12.04 affected
 jdstrand> -D_FORTIFY_SOURCE=2 in combination with ASLR and NX should
  adequately protect against this until an update is provided
Assigned-to
mdeslaur
Package
Source: sudo (LP Ubuntu Debian)
Upstream:released (1.8.3p2)
More Information

Updated: 2017-12-14 19:56:26 UTC (commit 13907)