7.4 HIGH
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
In Sudo through 1.9.17p2 before 3e474c2, a failure of a …
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
References
Affected products
- <3e474c2f201484be83d994ae10a4e20e8c81bb69
Matching in nixpkgs
pkgs.sudo
Command to run commands as root
pkgs.qsudo
Graphical sudo utility from Project Trident
-
nixos-unstable 2020.03.27
- nixpkgs-unstable 2020.03.27
- nixos-unstable-small 2020.03.27
-
nixos-25.11 2020.03.27
- nixos-25.11-small 2020.03.27
- nixpkgs-25.11-darwin 2020.03.27
pkgs.sudo-rs
Memory safe implementation of sudo and su
pkgs.psudohash
Password list generator for orchestrating brute force attacks and cracking hashes
pkgs.sudo-font
Font for programmers and command line users
pkgs.darwin.sudo
None
pkgs.gnome-sudoku
Test your logic skills in this number grid puzzle
pkgs.doas-sudo-shim
Shim for the sudo command that utilizes doas
pkgs.lxqt.lxqt-sudo
GUI frontend for sudo/su
pkgs.yaziPlugins.sudo
Call `sudo` in yazi
-
nixos-unstable 0-unstable-2025-11-05
- nixpkgs-unstable 0-unstable-2025-11-05
- nixos-unstable-small 0-unstable-2025-11-05
-
nixos-25.11 0-unstable-2025-11-05
- nixos-25.11-small 0-unstable-2025-11-05
- nixpkgs-25.11-darwin 0-unstable-2025-11-05
pkgs.libsForQt5.ksudoku
Suduko game
pkgs.kdePackages.ksudoku
KSudoku is a logic-based symbol placement puzzle
pkgs.plasma5Packages.ksudoku
Suduko game
pkgs.fishPlugins.plugin-sudope
Fish plugin to quickly put 'sudo' in your command
-
nixos-unstable 0-unstable-2025-09-16
- nixpkgs-unstable 0-unstable-2025-09-16
- nixos-unstable-small 0-unstable-2025-09-16
-
nixos-25.11 0-unstable-2025-09-16
- nixos-25.11-small 0-unstable-2025-09-16
- nixpkgs-25.11-darwin 0-unstable-2025-09-16
Package maintainers
-
@dani0854 Danil Suetin <suetin085+nixpkgs@protonmail.com>
-
@Anomalocaridid Duncan Russell <duncan@anomalocaris.xyz>
-
@bobby285271 Bobby Rong <rjl931189261@126.com>
-
@jtojnar Jan Tojnar <jtojnar@gmail.com>
-
@hedning Tor Hedin Brønner <torhedinbronner@gmail.com>
-
@dasj19 Daniel Șerbănescu <daniel@serbanescu.dk>
-
@LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
-
@K900 Ilya K. <me@0upti.me>
-
@ttuegel Thomas Tuegel <ttuegel@mailbox.org>
-
@ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru>
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@mjm Matt Moriarity <matt@mattmoriarity.com>
-
@romildo José Romildo Malaquias <malaquias@gmail.com>
-
@exploitoverload Asier Armenteros <nix@exploitoverload.com>
-
@rhendric Ryan Hendrickson
-
@nicoonoclaste nicoo <nicoo@debian.org>
-
@R-VdP Ramses <ramses@well-founded.dev>
-
@khaneliman Austin Horstman <khaneliman12@gmail.com>