PT-2010-1032 · Todd Miller+2 · Sudo+2

Anders Kaseorg

+1

·

Published

2010-06-07

·

Updated

2024-06-15

·

CVE-2010-1646

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions sudo versions 1.3.1 through 1.6.9p22 sudo versions 1.7.0 through 1.7.2p6
Description The issue is related to the secure path feature in sudo, which does not properly handle an environment containing multiple PATH variables. This could allow local users to gain privileges via a crafted value of the last PATH variable. Multiple vulnerabilities in the sudo package may lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited by a local attacker.
Recommendations For sudo versions 1.3.1 through 1.6.9p22, update to a version newer than 1.6.9p22 to resolve the issue. For sudo versions 1.7.0 through 1.7.2p6, update to a version newer than 1.7.2p6 to resolve the issue. As a temporary workaround, consider restricting access to the sudo functionality until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1056
BDU:2015-03065
BDU:2015-09416
CVE-2010-1646
DSA-2062-1
OPENSUSE-SU-2024:10551-1
RHSA-2010:0475
RHSA-2010_0475

Affected Products

Alt Linux
Red Hat
Sudo