Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-5602
HistoryNov 17, 2015 - 12:00 a.m.

CVE-2015-5602

2015-11-1700:00:00
ubuntu.com
ubuntu.com
29

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.001

Percentile

26.0%

sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a
symlink attack on a file whose full path is defined using multiple
wildcards in /etc/sudoers, as demonstrated by “/home///file.txt.”

Bugs

Notes

Author Note
mdeslaur Backporting the fix for this issue is risky, may introduce regressions, and will change behaviour for existing users, possibly preventing them from using their existing configuration. For this reason, we will not be fixing this issue in stable releases.

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.001

Percentile

26.0%