Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0106

Опубликовано: 06 мар. 2014
Источник: redhat
CVSS2: 6.6
EPSS Низкий

Описание

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

Отчет

This issue did not affect the version of sudo package as shipped with Red Hat Enterprise Linux 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sudoNot affected
Red Hat Enterprise Linux 7sudoNot affected
Red Hat Enterprise Linux 5sudoFixedRHSA-2014:026610.03.2014

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1071780sudo: certain environment variables not sanitized when env_reset is disabled

EPSS

Процентиль: 21%
0.00068
Низкий

6.6 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

nvd
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

debian
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly ...

github
больше 3 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

oracle-oval
больше 11 лет назад

ELSA-2014-0266: sudo security update (MODERATE)

EPSS

Процентиль: 21%
0.00068
Низкий

6.6 Medium

CVSS2