PT-2005-3804 · Sudo · Sudo

Tavis Ormandy

·

Published

2005-10-25

·

Updated

2018-10-03

·

CVE-2005-2959

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions sudo versions 1.6.8 and earlier
Description The issue allows local users to gain privileges via the SHELLOPTS and PS4 environment variables before executing a bash script on behalf of another user. These variables are not cleared, even though other variables are.
Recommendations For sudo versions 1.6.8 and earlier, consider clearing the SHELLOPTS and PS4 environment variables before executing a bash script on behalf of another user as a temporary workaround.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-2959
DSA-870-1

Affected Products

Sudo