PT-2005-3804 · Sudo · Sudo

Tavis Ormandy

·

Publicado

2005-10-25

·

Atualizado

2018-10-03

·

CVE-2005-2959

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions sudo versions 1.6.8 and earlier
Description The issue allows local users to gain privileges via the SHELLOPTS and PS4 environment variables before executing a bash script on behalf of another user. These variables are not cleared, even though other variables are.
Recommendations For sudo versions 1.6.8 and earlier, consider clearing the SHELLOPTS and PS4 environment variables before executing a bash script on behalf of another user as a temporary workaround.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-2959
DSA-870-1

Produtos afetados

Sudo