CVE-2010-0426
NONE EPSS 62.3%
Published Feb 24, 201016y ago · Modified Jun 16, 20262w ago
Published Feb 24, 2010 16y ago
Last Modified Jun 16, 2026 2w ago
Description
sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.
Threat Intelligence
EPSS Exploit Probability
62.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-264
Affected Products 32
| Vendor | Product | Version | Range |
|---|---|---|---|
| todd_miller | sudo | 1.6 | any |
| todd_miller | sudo | 1.6.1 | any |
| todd_miller | sudo | 1.6.2 | any |
| todd_miller | sudo | 1.6.3 | any |
| todd_miller | sudo | 1.6.3_p1 | any |
| todd_miller | sudo | 1.6.3_p2 | any |
| todd_miller | sudo | 1.6.3_p3 | any |
| todd_miller | sudo | 1.6.3_p4 | any |
| todd_miller | sudo | 1.6.3_p5 | any |
| todd_miller | sudo | 1.6.3_p6 | any |
| todd_miller | sudo | 1.6.3_p7 | any |
| todd_miller | sudo | 1.6.4_p1 | any |
| todd_miller | sudo | 1.6.4_p2 | any |
| todd_miller | sudo | 1.6.5_p1 | any |
| todd_miller | sudo | 1.6.5_p2 | any |
| todd_miller | sudo | 1.6.7_p5 | any |
| todd_miller | sudo | 1.6.8_p1 | any |
| todd_miller | sudo | 1.6.8_p2 | any |
| todd_miller | sudo | 1.6.8_p5 | any |
| todd_miller | sudo | 1.6.8_p7 | any |
| todd_miller | sudo | 1.6.8_p8 | any |
| todd_miller | sudo | 1.6.8_p9 | any |
| todd_miller | sudo | 1.6.8_p12 | any |
| todd_miller | sudo | 1.6.9_p17 | any |
| todd_miller | sudo | 1.6.9_p18 | any |
| todd_miller | sudo | 1.6.9_p19 | any |
| todd_miller | sudo | 1.7.0 | any |
| todd_miller | sudo | 1.7.1 | any |
| todd_miller | sudo | 1.7.2 | any |
| todd_miller | sudo | 1.7.2p1 | any |
| todd_miller | sudo | 1.7.2p2 | any |
| todd_miller | sudo | 1.7.2p3 | any |
References 29
- ftp.sudo.ws ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gz
- bugs.debian.org http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=570737
- lists.fedoraproject.org http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040578.html
- lists.fedoraproject.org http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040588.html
- lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html
- secunia.com http://secunia.com/advisories/38659
- secunia.com http://secunia.com/advisories/38762
- secunia.com http://secunia.com/advisories/38795
- secunia.com http://secunia.com/advisories/38803
- secunia.com http://secunia.com/advisories/38915
- secunia.com http://secunia.com/advisories/39399
- securitytracker.com http://securitytracker.com/id?1023658
- slackware.com http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.577019
- sudo.ws http://sudo.ws/bugs/show_bug.cgi?id=389
- sudo.ws http://sudo.ws/repos/sudo/rev/88f3181692fe
- sudo.ws http://sudo.ws/repos/sudo/rev/f86e1b56d074
- wiki.rpath.com http://wiki.rpath.com/Advisories:rPSA-2010-0075
- debian.org http://www.debian.org/security/2010/dsa-2006
- gentoo.org http://www.gentoo.org/security/en/glsa/glsa-201003-01.xml
- linuxquestions.org http://www.linuxquestions.org/questions/linux-security-4/the-use-of-sudoedit-command-question-785442/
- mandriva.com http://www.mandriva.com/security/advisories?name=MDVSA-2010:049
- securityfocus.com http://www.securityfocus.com/archive/1/514489/100/0/threaded
- securityfocus.com http://www.securityfocus.com/bid/38362
- sudo.ws http://www.sudo.ws/sudo/stable.html
- ubuntu.com http://www.ubuntu.com/usn/USN-905-1
- vupen.com http://www.vupen.com/english/advisories/2010/0450
- vupen.com http://www.vupen.com/english/advisories/2010/0949
- oval.cisecurity.org https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10814
- oval.cisecurity.org https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7238
Remediation
- ftp.sudo.ws ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gz
- securityfocus.com http://www.securityfocus.com/bid/38362
- sudo.ws http://www.sudo.ws/sudo/stable.html