VULNERABILITY INTELLIGENCE

CVE-2012-0809

CVSS score7.2 HIGH
EPSS probability2.93%
CISA KEVNot currently listed
Published2012-02-01
Last modified2026-06-16
CVSS vectorAV:L/AC:L/Au:N/C:C/I:C/A:C

Description

Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.

Weakness classification

  • CWE-134: Use of Externally-Controlled Format String

Primary references