Lucene search

K
cve[email protected]CVE-2005-2959
HistoryOct 25, 2005 - 4:02 p.m.

CVE-2005-2959

2005-10-2516:02:00
CWE-264
web.nvd.nist.gov
36
cve-2005-2959
incomplete blacklist
sudo
vulnerability
local users
privileges
shellopts
ps4
environment variables
bash script

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

High

EPSS

0

Percentile

9.5%

Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.

Affected configurations

NVD
Node
todd_millersudoMatch1.6
OR
todd_millersudoMatch1.6.1
OR
todd_millersudoMatch1.6.2
OR
todd_millersudoMatch1.6.3
OR
todd_millersudoMatch1.6.3_p1
OR
todd_millersudoMatch1.6.3_p2
OR
todd_millersudoMatch1.6.3_p3
OR
todd_millersudoMatch1.6.3_p4
OR
todd_millersudoMatch1.6.3_p5
OR
todd_millersudoMatch1.6.3_p6
OR
todd_millersudoMatch1.6.3_p7
OR
todd_millersudoMatch1.6.3p1
OR
todd_millersudoMatch1.6.3p2
OR
todd_millersudoMatch1.6.3p3
OR
todd_millersudoMatch1.6.3p4
OR
todd_millersudoMatch1.6.3p5
OR
todd_millersudoMatch1.6.3p6
OR
todd_millersudoMatch1.6.3p7
OR
todd_millersudoMatch1.6.4
OR
todd_millersudoMatch1.6.4_p1
OR
todd_millersudoMatch1.6.4_p2
OR
todd_millersudoMatch1.6.4p1
OR
todd_millersudoMatch1.6.4p2
OR
todd_millersudoMatch1.6.5
OR
todd_millersudoMatch1.6.5_p1
OR
todd_millersudoMatch1.6.5_p2
OR
todd_millersudoMatch1.6.5p1
OR
todd_millersudoMatch1.6.5p2
OR
todd_millersudoMatch1.6.6
OR
todd_millersudoMatch1.6.7
OR
todd_millersudoMatch1.6.7_p5
OR
todd_millersudoMatch1.6.8
VendorProductVersionCPE
todd_millersudo1.6cpe:/a:todd_miller:sudo:1.6:::
todd_millersudo1.6.3p2cpe:/a:todd_miller:sudo:1.6.3p2:::
todd_millersudo1.6.5cpe:/a:todd_miller:sudo:1.6.5:::
todd_millersudo1.6.3+p7cpe:/a:todd_miller:sudo:1.6.3+p7:::
todd_millersudo1.6.3+p4cpe:/a:todd_miller:sudo:1.6.3+p4:::
todd_millersudo1.6.7+p5cpe:/a:todd_miller:sudo:1.6.7+p5:::
todd_millersudo1.6.7cpe:/a:todd_miller:sudo:1.6.7:::
todd_millersudo1.6.4cpe:/a:todd_miller:sudo:1.6.4:::
todd_millersudo1.6.3p3cpe:/a:todd_miller:sudo:1.6.3p3:::
todd_millersudo1.6.1cpe:/a:todd_miller:sudo:1.6.1:::
Rows per page:
1-10 of 321

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

High

EPSS

0

Percentile

9.5%