PT-2005-4857 · Todd Miller · Sudo

Charles Morris

·

Publicado

2005-12-11

·

Atualizado

2024-06-15

·

CVE-2005-4158

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sudo versions prior to 1.6.8 p12
Description The issue allows limited local users to cause a Perl script to include and execute arbitrary library files. This is due to the failure to clear certain environment variables when the Perl taint flag is off. The variables PERLLIB, PERL5LIB, and PERL5OPT are not cleared, enabling the inclusion and execution of arbitrary library files with the same name as library files included by the script.
Recommendations For Sudo versions prior to 1.6.8 p12, update to version 1.6.8 p12 or later to resolve the issue. As a temporary workaround, consider setting the Perl taint flag to on to mitigate the risk of exploitation. Restrict access to the environment variables PERLLIB, PERL5LIB, and PERL5OPT to minimize the risk of arbitrary library file execution.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4158
DSA-946-2
OPENSUSE-SU-2024:11413-1

Produtos afetados

Sudo