Vulnerability Report

CVE-2019-19232

Title: Sudo

Other

Proof Of Concept

No public PoC currently indexed for CVE-2019-19232.

CWE Category NVD-CWE-noinfo
Published Date Dec 19, 2019
Modified Date Nov 21, 2024
Exploit Status Not Found
Score 7.5 CVSS v3.1
Exploit Probability (EPSS)
3.29%

Vulnerability Summary

CVE-2019-19232: In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional feature. Because this behavior surprised some users, sudo 1.8.30 introduced an option to enable/disable this behavior with the default being disabled. However, this does not change the fact that sudo was behaving as intended, and as documented, in earlier versions

Impacted Vendors

Reference Links

http://seclists.org/fulldisclosure/2020/Mar/31 https://access.redhat.com/security/cve/cve-2019-19232 https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I6TKF36KOQUVJNBHSVJFA7BU3CCEYD2F/ https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IY6DZ7WMDKU4ZDML6MJLDAPG42B5WVUC/ https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs58103 https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs58812 https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs58979 https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs76870 https://security.netapp.com/advisory/ntap-20200103-0004/ https://support.apple.com/en-gb/HT211100 https://support.apple.com/kb/HT211100 https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-19232 https://support2.windriver.com/index.php?page=defects&on=view&id=LIN1018-5506 https://www.bsi.bund.de/SharedDocs/Warnmeldungen/DE/CB/2019/12/warnmeldung_cb-k20-0001.html https://www.oracle.com/security-alerts/bulletinapr2020.html https://www.sudo.ws/devel.html#1.8.30b2 https://www.sudo.ws/stable.html https://www.tenable.com/plugins/nessus/133936 http://seclists.org/fulldisclosure/2020/Mar/31 https://access.redhat.com/security/cve/cve-2019-19232 https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I6TKF36KOQUVJNBHSVJFA7BU3CCEYD2F/ https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IY6DZ7WMDKU4ZDML6MJLDAPG42B5WVUC/ https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs58103 https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs58812 https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs58979 https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs76870 https://security.netapp.com/advisory/ntap-20200103-0004/ https://support.apple.com/en-gb/HT211100 https://support.apple.com/kb/HT211100 https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2019-19232 https://support2.windriver.com/index.php?page=defects&on=view&id=LIN1018-5506 https://www.bsi.bund.de/SharedDocs/Warnmeldungen/DE/CB/2019/12/warnmeldung_cb-k20-0001.html https://www.oracle.com/security-alerts/bulletinapr2020.html https://www.sudo.ws/devel.html#1.8.30b2 https://www.sudo.ws/stable.html https://www.tenable.com/plugins/nessus/133936
CVSS v3.1
Source Entity [email protected]
Severity HIGH
7.5
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0
Source Entity [email protected]
Severity MEDIUM
5.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:L/Au:N/C:N/I:P/A:N

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2019-19232 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector NETWORK
Complexity LOW
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Stack

No specific products linked.