Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-0106

Опубликовано: 11 мар. 2014
Источник: debian
EPSS Низкий

Описание

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sudofixed1.8.5p2-1package
sudono-dsasqueezepackage

Примечания

  • http://www.sudo.ws/sudo/alerts/env_add.html

EPSS

Процентиль: 21%
0.00068
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

redhat
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

nvd
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

github
больше 3 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

oracle-oval
больше 11 лет назад

ELSA-2014-0266: sudo security update (MODERATE)

EPSS

Процентиль: 21%
0.00068
Низкий