VULNERABILITY INTELLIGENCE
CVE-2012-0809
CVSS score7.2 HIGH
EPSS probability2.93%
CISA KEVNot currently listed
Published2012-02-01
Last modified2026-06-16
CVSS vectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Description
Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.
Weakness classification
- CWE-134: Use of Externally-Controlled Format String
Primary references
- secalert@redhat.com
- secalert@redhat.com — Exploit
- secalert@redhat.com
- secalert@redhat.com — Exploit, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108 — Exploit
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108 — Exploit, Vendor Advisory