PT-2010-1078 · Todd Miller+2 · Sudo+2

Published

2010-02-24

·

Updated

2018-10-10

·

CVE-2010-0426

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions sudo versions 1.6.x through 1.6.9p20 sudo versions 1.7.x through 1.7.2p3
Description The issue allows local users to gain privileges via a crafted executable file, potentially leading to a breach of confidentiality, integrity, and availability of protected information. This can be achieved by exploiting a match between the name of a pseudo-command and the name of an executable file in an arbitrary directory. For example, a file named sudoedit in a user's home directory can be used for exploitation. The estimated number of potentially affected devices is not provided.
Recommendations For sudo versions 1.6.x through 1.6.9p20, update to version 1.6.9p21 or later. For sudo versions 1.7.x through 1.7.2p3, update to version 1.7.2p4 or later. As a temporary workaround, consider disabling the pseudo-command feature until a patch is available. Restrict access to arbitrary directories to minimize the risk of exploitation. Avoid using crafted executable files in user directories until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2014
ALT-PU-2017-1056
BDU:2015-08594
BDU:2015-09414
CESA-2012_1081
CESA-2013_1701
CESA-2015_1409
CESA-2016_2872
CVE-2010-0426
DSA-2006-1
RHSA-2010:0122
RHSA-2010_0122
RHSA-2010_0361
RHSA-2010_0475
RHSA-2012_1081
RHSA-2013_1353
RHSA-2013_1701
RHSA-2015_1409
RHSA-2016_2872

Affected Products

Alt Linux
Red Hat
Sudo