CVE-2025-32462

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*
cpe:2.3:a:sudo_project:sudo:1.9.17:-:*:*:*:*:*:*

History

03 Nov 2025, 20:18

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/06/msg00033.html -

Information

Published : 2025-06-30 21:15

Updated : 2025-11-03 20:18


NVD link : CVE-2025-32462

Mitre link : CVE-2025-32462

CVE.ORG link : CVE-2025-32462


JSON object : View

Products Affected

sudo_project

  • sudo
CWE
CWE-863

Incorrect Authorization