Skip to navigation

CVE Database

CVE-2013-1775

Impact: Low
Public: 2013-02-27
Bugzilla: 916363: CVE-2013-1775 sudo: authentication bypass via reset system clock
IAVA: 2013-A-0179

Details

The MITRE CVE dictionary describes this issue as:

sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch.

Find out more about CVE-2013-1775 from the MITRE CVE dictionary and NIST NVD.

CVSS v2 metrics

Base Score: 2.1
Base Metrics: AV:L/AC:L/Au:N/C:N/I:P/A:N
Access Vector: Local
Access Complexity: Low
Authentication: None
Confidentiality Impact: None
Integrity Impact: Partial
Availability Impact: None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat security errata

Platform Errata Release Date
Red Hat Enterprise Linux version 5 (sudo) RHSA-2013:1353 September 30, 2013
Red Hat Enterprise Linux version 6 (sudo) RHSA-2013:1701 November 20, 2013

External References

http://www.sudo.ws/sudo/alerts/epoch_ticket.html

This page is generated automatically and has not been checked for errors or omissions.

For clarification or corrections please contact the Red Hat Security Response Team.