Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxvm-3g7g-7vv7

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

EPSS

Процентиль: 21%
0.00068
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

redhat
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

nvd
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

debian
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly ...

oracle-oval
больше 11 лет назад

ELSA-2014-0266: sudo security update (MODERATE)

EPSS

Процентиль: 21%
0.00068
Низкий

Дефекты

CWE-20