Lucene search

K
ubuntucveUbuntu.comUB:CVE-2005-4158
HistoryDec 11, 2005 - 12:00 a.m.

CVE-2005-4158

2005-12-1100:00:00
ubuntu.com
ubuntu.com
16

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

0.4%

Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the
(1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which
allows limited local users to cause a Perl script to include and execute
arbitrary library files that have the same name as library files that are
included by the script.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchsudo< 1.6.8p12-1ubuntu6UNKNOWN
ubuntu6.10noarchsudo< 1.6.8p12-1ubuntu6UNKNOWN
ubuntu7.04noarchsudo< 1.6.8p12-1ubuntu6UNKNOWN

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

0.4%