CVE detail
CVE-2014-9680 — CVE-2014-9680
Published 2017-04-24 · Modified 2026-06-17 · Vendor sudo_project · Product sudo · Source nvd
LOW
severity
CVSS-derived band
0.0047
EPSS probability
exploitation probability, 30d
38.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References