Bug 949751 (CVE-2013-2776)

Summary: CVE-2013-2776 sudo: bypass of tty_tickets constraints
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: dkopecek, kzak
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: sudo 1.8.6p7, sudo 1.7.10p6 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-11-22 05:36:34 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 968221, 1015355    
Bug Blocks: 916366, 952520, 974906    

Description Vincent Danen 2013-04-08 22:35:39 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2776 to
the following vulnerability:

Name: CVE-2013-2776
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2776
Assigned: 20130408
Reference: http://www.openwall.com/lists/oss-security/2013/02/27/31
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=916365
Reference: http://www.sudo.ws/repos/sudo/rev/049a12a5cc14
Reference: http://www.sudo.ws/repos/sudo/rev/0c0283d1fafa
Reference: http://www.sudo.ws/sudo/alerts/tty_tickets.html
Reference: http://www.securityfocus.com/bid/58207

sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on
systems without /proc or the sysctl function with the tty_tickets
option enabled, does not properly validate the controlling terminal
device, which allows local users with sudo permissions to hijack the
authorization of another terminal via vectors related to connecting to
a standard input, output, and error file descriptors of another
terminal.  NOTE: this is one of three closely-related vulnerabilities
that were originally assigned CVE-2013-1776, but they have been SPLIT
because of different affected versions.

Comment 2 errata-xmlrpc 2013-10-01 00:29:41 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2013:1353 https://rhn.redhat.com/errata/RHSA-2013-1353.html

Comment 6 Tomas Hoger 2013-10-09 20:52:48 UTC
This CVE split out of CVE-2013-1776 is for a sudo enhancement that makes sudo store session id in a ticket file to disallow use of the ticket by a process from a different session.

Comment 7 errata-xmlrpc 2013-11-21 23:12:47 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:1701 https://rhn.redhat.com/errata/RHSA-2013-1701.html

Comment 8 Huzaifa S. Sidhpurwala 2013-11-22 05:36:34 UTC
Statement:

(none)