Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.
https://www.sudo.ws/alerts/linux_tty.html
https://usn.ubuntu.com/3968-2/
https://usn.ubuntu.com/3968-1/
https://security.gentoo.org/glsa/201710-04
https://kc.mcafee.com/corporate/index?page=content&id=SB10205