Lucene search

K
ubuntucveUbuntu.comUB:CVE-2005-2959
HistoryOct 25, 2005 - 12:00 a.m.

CVE-2005-2959

2005-10-2500:00:00
ubuntu.com
ubuntu.com
13

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

9.5%

Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local
users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment
variables before executing a bash script on behalf of another user, which
are not cleared even though other variables are.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchsudo< 1.6.8p12-1ubuntu6UNKNOWN
ubuntu6.10noarchsudo< 1.6.8p12-1ubuntu6UNKNOWN
ubuntu7.04noarchsudo< 1.6.8p12-1ubuntu6UNKNOWN

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

9.5%