Apple Computer Inc. Not Affected

Notified:  September 28, 2004 Updated: February 17, 2005

Status

Not Affected

Vendor Statement

Mac OS X and Mac OS X Server do not contain this issue as the vulnerable versions of sudo were not distributed.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

BSDI Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Conectiva Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Cray Inc. Not Affected

Notified:  September 28, 2004 Updated: September 29, 2004

Status

Not Affected

Vendor Statement

Cray Inc. supports sudo through its Cray Open Software (COS) package. The sudo version in COS 3.5 and later is not vulnerable.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

Previous versions of COS are also not vulnerable.

Debian Not Affected

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Not Affected

Vendor Statement

No release of Debian contains sudo 1.6.8, nor has it entered our unstable development tree, so we are not affected by this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

EMC Corporation Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Engarde Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

F5 Networks Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

FreeBSD Affected

Notified:  September 28, 2004 Updated: September 29, 2004

Status

Affected

Vendor Statement

Sudo was corrected in the FreeBSD Ports Collection on September 19. The issue is documented at http://vuxml.freebsd.org/a268ef4a-0b35-11d9-8a8a-000c41e2cdad.html

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Fujitsu Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Gentoo Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Hewlett-Packard Company Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Hitachi Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

IBM Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

IBM eServer Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

IBM-zSeries Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Immunix Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Ingrian Networks Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Juniper Networks Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

MandrakeSoft Not Affected

Notified:  September 28, 2004 Updated: September 29, 2004

Status

Not Affected

Vendor Statement

Mandrakesoft does not ship this version of sudo in any of it's products so is not vulnerable to this problem.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

MontaVista Software Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

NEC Corporation Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

NETBSD Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Nokia Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Novell Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

OpenBSD Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Openwall GNU/*/Linux Not Affected

Notified:  September 28, 2004 Updated: September 29, 2004

Status

Not Affected

Vendor Statement

Openwall GNU/*/Linux is not vulnerable. We do not package sudo.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Redhat Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

SCO Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Sequent Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

SGI Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Sony Corporation Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Sun Microsystems Inc. Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

SuSE Inc. Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

TurboLinux Not Affected

Notified:  September 28, 2004 Updated: September 29, 2004

Status

Not Affected

Vendor Statement

Not vulnerable. Turbolinux prodcuts do not contain this issue.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Unisys Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

Wind River Systems Inc. Unknown

Notified:  September 28, 2004 Updated: September 28, 2004

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

We have no additional comments at this time.

View all 37 vendors View less vendors