CVE-2012-2337: Todd Miller Sudo

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.

Affected products

  • Todd Miller Sudo: version 1.6 only; version 1.6.1 only; version 1.6.2 only; version 1.6.2p3 only; version 1.6.3 only; version 1.6.3_p7 only; …

Published 2012-05-18. Last modified 2026-06-16.