Bug 949751 - (CVE-2013-2776) CVE-2013-2776 sudo: bypass of tty_tickets constraints
CVE-2013-2776 sudo: bypass of tty_tickets constraints
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 968221 1015355
Blocks: 916366 952520 974906
  Show dependency treegraph
Reported: 2013-04-08 18:35 EDT by Vincent Danen
Modified: 2013-11-22 00:36 EST (History)
2 users (show)

See Also:
Fixed In Version: sudo 1.8.6p7, sudo 1.7.10p6
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2013-11-22 00:36:34 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Vincent Danen 2013-04-08 18:35:39 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2776 to
the following vulnerability:

Name: CVE-2013-2776
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2776
Assigned: 20130408
Reference: http://www.openwall.com/lists/oss-security/2013/02/27/31
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=916365
Reference: http://www.sudo.ws/repos/sudo/rev/049a12a5cc14
Reference: http://www.sudo.ws/repos/sudo/rev/0c0283d1fafa
Reference: http://www.sudo.ws/sudo/alerts/tty_tickets.html
Reference: http://www.securityfocus.com/bid/58207

sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on
systems without /proc or the sysctl function with the tty_tickets
option enabled, does not properly validate the controlling terminal
device, which allows local users with sudo permissions to hijack the
authorization of another terminal via vectors related to connecting to
a standard input, output, and error file descriptors of another
terminal.  NOTE: this is one of three closely-related vulnerabilities
that were originally assigned CVE-2013-1776, but they have been SPLIT
because of different affected versions.
Comment 2 errata-xmlrpc 2013-09-30 20:29:41 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2013:1353 https://rhn.redhat.com/errata/RHSA-2013-1353.html
Comment 6 Tomas Hoger 2013-10-09 16:52:48 EDT
This CVE split out of CVE-2013-1776 is for a sudo enhancement that makes sudo store session id in a ticket file to disallow use of the ticket by a process from a different session.
Comment 7 errata-xmlrpc 2013-11-21 18:12:47 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:1701 https://rhn.redhat.com/errata/RHSA-2013-1701.html
Comment 8 Huzaifa S. Sidhpurwala 2013-11-22 00:36:34 EST


Note You need to log in before you can comment on or make changes to this bug.