CVE-2010-0426

NONE EPSS 62.3%
Published Feb 24, 201016y ago · Modified Jun 16, 20262w ago
Find Similar
Published Feb 24, 2010 16y ago
Last Modified Jun 16, 2026 2w ago

Description

sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.

Threat Intelligence

EPSS Exploit Probability
62.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-264

Affected Products 32

VendorProductVersionRange
todd_millersudo1.6any
todd_millersudo1.6.1any
todd_millersudo1.6.2any
todd_millersudo1.6.3any
todd_millersudo1.6.3_p1any
todd_millersudo1.6.3_p2any
todd_millersudo1.6.3_p3any
todd_millersudo1.6.3_p4any
todd_millersudo1.6.3_p5any
todd_millersudo1.6.3_p6any
todd_millersudo1.6.3_p7any
todd_millersudo1.6.4_p1any
todd_millersudo1.6.4_p2any
todd_millersudo1.6.5_p1any
todd_millersudo1.6.5_p2any
todd_millersudo1.6.7_p5any
todd_millersudo1.6.8_p1any
todd_millersudo1.6.8_p2any
todd_millersudo1.6.8_p5any
todd_millersudo1.6.8_p7any
todd_millersudo1.6.8_p8any
todd_millersudo1.6.8_p9any
todd_millersudo1.6.8_p12any
todd_millersudo1.6.9_p17any
todd_millersudo1.6.9_p18any
todd_millersudo1.6.9_p19any
todd_millersudo1.7.0any
todd_millersudo1.7.1any
todd_millersudo1.7.2any
todd_millersudo1.7.2p1any
todd_millersudo1.7.2p2any
todd_millersudo1.7.2p3any

References 29

  • ftp.sudo.ws ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gz
    Patch
  • bugs.debian.org http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=570737
  • lists.fedoraproject.org http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040578.html
  • lists.fedoraproject.org http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040588.html
  • lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html
  • secunia.com http://secunia.com/advisories/38659
    Vendor Advisory
  • secunia.com http://secunia.com/advisories/38762
  • secunia.com http://secunia.com/advisories/38795
  • secunia.com http://secunia.com/advisories/38803
  • secunia.com http://secunia.com/advisories/38915
  • secunia.com http://secunia.com/advisories/39399
  • securitytracker.com http://securitytracker.com/id?1023658
  • slackware.com http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.577019
  • sudo.ws http://sudo.ws/bugs/show_bug.cgi?id=389
  • sudo.ws http://sudo.ws/repos/sudo/rev/88f3181692fe
  • sudo.ws http://sudo.ws/repos/sudo/rev/f86e1b56d074
  • wiki.rpath.com http://wiki.rpath.com/Advisories:rPSA-2010-0075
  • debian.org http://www.debian.org/security/2010/dsa-2006
  • gentoo.org http://www.gentoo.org/security/en/glsa/glsa-201003-01.xml
  • linuxquestions.org http://www.linuxquestions.org/questions/linux-security-4/the-use-of-sudoedit-command-question-785442/
  • mandriva.com http://www.mandriva.com/security/advisories?name=MDVSA-2010:049
  • securityfocus.com http://www.securityfocus.com/archive/1/514489/100/0/threaded
  • securityfocus.com http://www.securityfocus.com/bid/38362
    Patch
  • sudo.ws http://www.sudo.ws/sudo/stable.html
    Patch
  • ubuntu.com http://www.ubuntu.com/usn/USN-905-1
  • vupen.com http://www.vupen.com/english/advisories/2010/0450
    Vendor Advisory
  • vupen.com http://www.vupen.com/english/advisories/2010/0949
  • oval.cisecurity.org https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10814
  • oval.cisecurity.org https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7238

Remediation

  • ftp.sudo.ws ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gz
    Patch
  • securityfocus.com http://www.securityfocus.com/bid/38362
    Patch
  • sudo.ws http://www.sudo.ws/sudo/stable.html
    Patch