Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0106

Опубликовано: 11 мар. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.6

Описание

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

РелизСтатусПримечание
devel

not-affected

lucid

released

1.7.2p1-1ubuntu5.7
precise

released

1.8.3p1-1ubuntu3.6
quantal

not-affected

1.8.5p2-1ubuntu1.1
saucy

not-affected

upstream

released

1.8.5

Показывать по

EPSS

Процентиль: 21%
0.00068
Низкий

6.6 Medium

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

nvd
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

debian
больше 11 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly ...

github
больше 3 лет назад

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

oracle-oval
больше 11 лет назад

ELSA-2014-0266: sudo security update (MODERATE)

EPSS

Процентиль: 21%
0.00068
Низкий

6.6 Medium

CVSS2