PT-2010-1032 · Todd Miller+2 · Sudo+2

Anders Kaseorg

+1

·

Publicado

2010-06-07

·

Atualizado

2024-06-15

·

CVE-2010-1646

CVSS v2.0

6.2

Média

VetorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions sudo versions 1.3.1 through 1.6.9p22 sudo versions 1.7.0 through 1.7.2p6
Description The issue is related to the secure path feature in sudo, which does not properly handle an environment containing multiple PATH variables. This could allow local users to gain privileges via a crafted value of the last PATH variable. Multiple vulnerabilities in the sudo package may lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited by a local attacker.
Recommendations For sudo versions 1.3.1 through 1.6.9p22, update to a version newer than 1.6.9p22 to resolve the issue. For sudo versions 1.7.0 through 1.7.2p6, update to a version newer than 1.7.2p6 to resolve the issue. As a temporary workaround, consider restricting access to the sudo functionality until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1056
BDU:2015-03065
BDU:2015-09416
CVE-2010-1646
DSA-2062-1
OPENSUSE-SU-2024:10551-1
RHSA-2010:0475
RHSA-2010_0475

Produtos afetados

Alt Linux
Red Hat
Sudo