Required CVE Record Information
Description
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
References 37 Total
- openwall.com: [oss-security] 20191014 Sudo: CVE-2019-14287 mailing-list
- usn.ubuntu.com: USN-4154-1 vendor-advisory
- debian.org: DSA-4543 vendor-advisory
- seclists.org: 20191015 [SECURITY] [DSA 4543-1] sudo security update mailing-list
- seclists.org: 20191015 [slackware-security] sudo (SSA:2019-287-01) mailing-list
- lists.opensuse.org: openSUSE-SU-2019:2316 vendor-advisory
- http://packetstormsecurity.com/files/154853/Slackware-Security-Advisory-sudo-Updates.html
- lists.fedoraproject.org: FEDORA-2019-9cb221f2be vendor-advisory
- https://www.sudo.ws/alerts/minus_1_uid.html
- lists.opensuse.org: openSUSE-SU-2019:2333 vendor-advisory
- https://security.netapp.com/advisory/ntap-20191017-0003/
- openwall.com: [oss-security] 20191015 Re: Sudo: CVE-2019-14287 mailing-list
- lists.debian.org: [debian-lts-announce] 20191017 [SECURITY] [DLA 1964-1] sudo security update mailing-list
- lists.fedoraproject.org: FEDORA-2019-67998e9f7e vendor-advisory
- https://support.f5.com/csp/article/K53746212?utm_source=f5support&%3Butm_medium=RSS
- openwall.com: [oss-security] 20191023 Membership application for linux-distros - VMware mailing-list
- access.redhat.com: RHSA-2019:3197 vendor-advisory
- access.redhat.com: RHSA-2019:3205 vendor-advisory
- access.redhat.com: RHSA-2019:3204 vendor-advisory
- access.redhat.com: RHSA-2019:3209 vendor-advisory
- access.redhat.com: RHSA-2019:3219 vendor-advisory
- openwall.com: [oss-security] 20191029 Re: Membership application for linux-distros - VMware mailing-list
- lists.fedoraproject.org: FEDORA-2019-72755db9c7 vendor-advisory
- access.redhat.com: RHSA-2019:3278 vendor-advisory
- https://resources.whitesourcesoftware.com/blog-whitesource/new-vulnerability-in-sudo-cve-2019-14287
- access.redhat.com: RHSA-2019:3694 vendor-advisory
- access.redhat.com: RHSA-2019:3755 vendor-advisory
- access.redhat.com: RHSA-2019:3754 vendor-advisory
- access.redhat.com: RHSA-2019:3895 vendor-advisory
- access.redhat.com: RHSA-2019:3916 vendor-advisory
- access.redhat.com: RHBA-2019:3248 vendor-advisory
- access.redhat.com: RHSA-2019:3941 vendor-advisory
- access.redhat.com: RHSA-2019:4191 vendor-advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03976en_us
- access.redhat.com: RHSA-2020:0388 vendor-advisory
- security.gentoo.org: GLSA-202003-12 vendor-advisory
- openwall.com: [oss-security] 20210914 Re: Oracle Solaris membership in the distros list mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 37 Total
- openwall.com: [oss-security] 20191014 Sudo: CVE-2019-14287 mailing-listx_transferred
- usn.ubuntu.com: USN-4154-1 vendor-advisoryx_transferred
- debian.org: DSA-4543 vendor-advisoryx_transferred
- seclists.org: 20191015 [SECURITY] [DSA 4543-1] sudo security update mailing-listx_transferred
- seclists.org: 20191015 [slackware-security] sudo (SSA:2019-287-01) mailing-listx_transferred
- lists.opensuse.org: openSUSE-SU-2019:2316 vendor-advisoryx_transferred
- http://packetstormsecurity.com/files/154853/Slackware-Security-Advisory-sudo-Updates.html x_transferred
- lists.fedoraproject.org: FEDORA-2019-9cb221f2be vendor-advisoryx_transferred
- https://www.sudo.ws/alerts/minus_1_uid.html x_transferred
- lists.opensuse.org: openSUSE-SU-2019:2333 vendor-advisoryx_transferred
- https://security.netapp.com/advisory/ntap-20191017-0003/ x_transferred
- openwall.com: [oss-security] 20191015 Re: Sudo: CVE-2019-14287 mailing-listx_transferred
- lists.debian.org: [debian-lts-announce] 20191017 [SECURITY] [DLA 1964-1] sudo security update mailing-listx_transferred
- lists.fedoraproject.org: FEDORA-2019-67998e9f7e vendor-advisoryx_transferred
- https://support.f5.com/csp/article/K53746212?utm_source=f5support&%3Butm_medium=RSS x_transferred
- openwall.com: [oss-security] 20191023 Membership application for linux-distros - VMware mailing-listx_transferred
- access.redhat.com: RHSA-2019:3197 vendor-advisoryx_transferred
- access.redhat.com: RHSA-2019:3205 vendor-advisoryx_transferred
- access.redhat.com: RHSA-2019:3204 vendor-advisoryx_transferred
- access.redhat.com: RHSA-2019:3209 vendor-advisoryx_transferred
- access.redhat.com: RHSA-2019:3219 vendor-advisoryx_transferred
- openwall.com: [oss-security] 20191029 Re: Membership application for linux-distros - VMware mailing-listx_transferred
- lists.fedoraproject.org: FEDORA-2019-72755db9c7 vendor-advisoryx_transferred
- access.redhat.com: RHSA-2019:3278 vendor-advisoryx_transferred
- https://resources.whitesourcesoftware.com/blog-whitesource/new-vulnerability-in-sudo-cve-2019-14287 x_transferred
- access.redhat.com: RHSA-2019:3694 vendor-advisoryx_transferred
- access.redhat.com: RHSA-2019:3755 vendor-advisoryx_transferred
- access.redhat.com: RHSA-2019:3754 vendor-advisoryx_transferred
- access.redhat.com: RHSA-2019:3895 vendor-advisoryx_transferred
- access.redhat.com: RHSA-2019:3916 vendor-advisoryx_transferred
- access.redhat.com: RHBA-2019:3248 vendor-advisoryx_transferred
- access.redhat.com: RHSA-2019:3941 vendor-advisoryx_transferred
- access.redhat.com: RHSA-2019:4191 vendor-advisoryx_transferred
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03976en_us x_transferred
- access.redhat.com: RHSA-2020:0388 vendor-advisoryx_transferred
- security.gentoo.org: GLSA-202003-12 vendor-advisoryx_transferred
- openwall.com: [oss-security] 20210914 Re: Oracle Solaris membership in the distros list mailing-listx_transferred