Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
{ "binaries": [ { "binary_version": "1.9.15p5-3ubuntu5.24.04.1", "binary_name": "libnss-sudo" }, { "binary_version": "1.9.15p5-3ubuntu5.24.04.1", "binary_name": "sudo" }, { "binary_version": "1.9.15p5-3ubuntu5.24.04.1", "binary_name": "sudo-dbgsym" }, { "binary_version": "1.9.15p5-3ubuntu5.24.04.1", "binary_name": "sudo-ldap" }, { "binary_version": "1.9.15p5-3ubuntu5.24.04.1", "binary_name": "sudo-ldap-dbgsym" } ], "priority_reason": "Allows local privilege escalation", "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "1.9.16p2-1ubuntu1.1", "binary_name": "libnss-sudo" }, { "binary_version": "1.9.16p2-1ubuntu1.1", "binary_name": "sudo" }, { "binary_version": "1.9.16p2-1ubuntu1.1", "binary_name": "sudo-dbgsym" }, { "binary_version": "1.9.16p2-1ubuntu1.1", "binary_name": "sudo-ldap" }, { "binary_version": "1.9.16p2-1ubuntu1.1", "binary_name": "sudo-ldap-dbgsym" } ], "priority_reason": "Allows local privilege escalation", "availability": "No subscription required" }