Related Vulnerabilities: CVE-2019-14287  

A flaw was found in the way sudo implemented running commands with arbitrary user ID. If a sudoers entry is written to allow the attacker to run a command as any user except root, this flaw can be used by the attacker to bypass that restriction.

Severity High

Remote No

Type Arbitrary code execution

Description

A flaw was found in the way sudo implemented running commands with arbitrary user ID. If a sudoers entry is written to allow the attacker to run a command as any user except root, this flaw can be used by the attacker to bypass that restriction.

AVG-1047 sudo 1.8.27-1 1.8.28-1 High Fixed

https://www.sudo.ws/alerts/minus_1_uid.html
https://www.sudo.ws/repos/sudo/rev/83db8dba09e7