The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.
References
Link Resource
http://www.openwall.com/lists/oss-security/2015/11/18/22 Mailing List Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1283635 Issue Tracking Patch Third Party Advisory
https://www.sudo.ws/repos/sudo/rev/0cd3cc8fa195 Issue Tracking Patch Third Party Advisory
https://www.sudo.ws/repos/sudo/rev/24a3d9215c64 Issue Tracking Patch Third Party Advisory
https://www.sudo.ws/repos/sudo/rev/397722cdd7ec Issue Tracking Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-10-10T16:00:00

Updated: 2017-10-10T15:57:01

Reserved: 2015-11-18T00:00:00


Link: CVE-2015-8239

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-10-10T16:29:00.557

Modified: 2017-11-05T21:23:16.497


Link: CVE-2015-8239

JSON object: View

cve-icon Redhat Information

No data.

CWE