Lucene search

K
ubuntucveUbuntu.comUB:CVE-2004-1051
HistoryMar 01, 2005 - 12:00 a.m.

CVE-2004-1051

2005-03-0100:00:00
ubuntu.com
ubuntu.com
11

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

0.001 Low

EPSS

Percentile

25.6%

sudo before 1.6.8p2 allows local users to execute arbitrary commands by
using “()” style environment variables to create functions that have the
same name as any program within the bash script that is called without
using the program’s full pathname.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchsudo< 1.6.8p12-1ubuntu6UNKNOWN
ubuntu6.10noarchsudo< 1.6.8p12-1ubuntu6UNKNOWN
ubuntu7.04noarchsudo< 1.6.8p12-1ubuntu6UNKNOWN

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

0.001 Low

EPSS

Percentile

25.6%