PublicDateAtUSN: 2012-05-16 14:00:00 Candidate: CVE-2012-2337 CRD: 2012-05-16 14:00:00 PublicDate: 2012-05-18 18:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2337 http://www.sudo.ws/sudo/alerts/netmask.html https://ubuntu.com/security/notices/USN-1442-1 Description: sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address. Ubuntu-Description: Notes: tyhicks> Not easy to reproduce and requires that the user exploiting this flaw to already be specified in the sudoers file Bugs: https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/1000276 Priority: medium Discovered-by: Assigned-to: tyhicks CVSS: Patches_sudo: upstream: http://www.sudo.ws/repos/sudo/rev/80b1e4a6d4a1 vendor: http://www.debian.org/security/2012/dsa-2478 upstream_sudo: released (1.8.4p5) hardy_sudo: released (1.6.9p10-1ubuntu3.9) lucid_sudo: released (1.7.2p1-1ubuntu5.4) natty_sudo: released (1.7.4p4-5ubuntu7.2) oneiric_sudo: released (1.7.4p6-1ubuntu2.1) precise_sudo: released (1.8.3p1-1ubuntu3.2) devel_sudo: released (1.8.3p1-1ubuntu5)