Bug 949751 (CVE-2013-2776) - CVE-2013-2776 sudo: bypass of tty_tickets constraints
Summary: CVE-2013-2776 sudo: bypass of tty_tickets constraints
Alias: CVE-2013-2776
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 968221 1015355
Blocks: 916366 952520 974906
TreeView+ depends on / blocked
Reported: 2013-04-08 22:35 UTC by Vincent Danen
Modified: 2021-02-17 07:51 UTC (History)
2 users (show)

Fixed In Version: sudo 1.8.6p7, sudo 1.7.10p6
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2013-11-22 05:36:34 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2013:1353 0 normal SHIPPED_LIVE Low: sudo security and bug fix update 2013-10-01 00:31:10 UTC
Red Hat Product Errata RHSA-2013:1701 0 normal SHIPPED_LIVE Low: sudo security, bug fix and enhancement update 2013-11-20 21:52:06 UTC

Description Vincent Danen 2013-04-08 22:35:39 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2776 to
the following vulnerability:

Name: CVE-2013-2776
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2776
Assigned: 20130408
Reference: http://www.openwall.com/lists/oss-security/2013/02/27/31
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=916365
Reference: http://www.sudo.ws/repos/sudo/rev/049a12a5cc14
Reference: http://www.sudo.ws/repos/sudo/rev/0c0283d1fafa
Reference: http://www.sudo.ws/sudo/alerts/tty_tickets.html
Reference: http://www.securityfocus.com/bid/58207

sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on
systems without /proc or the sysctl function with the tty_tickets
option enabled, does not properly validate the controlling terminal
device, which allows local users with sudo permissions to hijack the
authorization of another terminal via vectors related to connecting to
a standard input, output, and error file descriptors of another
terminal.  NOTE: this is one of three closely-related vulnerabilities
that were originally assigned CVE-2013-1776, but they have been SPLIT
because of different affected versions.

Comment 2 errata-xmlrpc 2013-10-01 00:29:41 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2013:1353 https://rhn.redhat.com/errata/RHSA-2013-1353.html

Comment 6 Tomas Hoger 2013-10-09 20:52:48 UTC
This CVE split out of CVE-2013-1776 is for a sudo enhancement that makes sudo store session id in a ticket file to disallow use of the ticket by a process from a different session.

Comment 7 errata-xmlrpc 2013-11-21 23:12:47 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:1701 https://rhn.redhat.com/errata/RHSA-2013-1701.html

Comment 8 Huzaifa S. Sidhpurwala 2013-11-22 05:36:34 UTC


Note You need to log in before you can comment on or make changes to this bug.