PublicDateAtUSN: 2014-12-31 Candidate: CVE-2014-9680 PublicDate: 2017-04-24 06:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9680 http://www.openwall.com/lists/oss-security/2014/10/15/24 http://www.openwall.com/lists/oss-security/2015/02/09/12 http://www.sudo.ws/sudo/alerts/tz.html https://ubuntu.com/security/notices/USN-2533-1 Description: sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=772707 Priority: medium Discovered-by: Jakub Wilk and Stephane Chazelas Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N [3.3 LOW] Patches_sudo: upstream: http://www.sudo.ws/repos/sudo/rev/650ac6938b59 (1.8) upstream: http://www.sudo.ws/repos/sudo/rev/ac1467f71ac0 (1.8) upstream: http://www.sudo.ws/repos/sudo/rev/91859f613b88 (1.8) upstream: http://www.sudo.ws/repos/sudo/rev/579b02f0dbe0 (1.8) upstream: http://www.sudo.ws/repos/sudo/rev/33b545d19c03 (1.7) upstream_sudo: released (1.7.10p9, 1.8.12) lucid_sudo: released (1.7.2p1-1ubuntu5.8) precise_sudo: released (1.8.3p1-1ubuntu3.7) trusty_sudo: released (1.8.9p5-1ubuntu1.1) trusty/esm_sudo: released (1.8.9p5-1ubuntu1.1) utopic_sudo: released (1.8.9p5-1ubuntu2.1) devel_sudo: released (1.8.9p5-1ubuntu5)