← Back

CVE-2004-1051

nvd nist
Published: Mar 1, 2005Modified: Apr 16, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.

Affected (51)

Show all products
3 products
Mandrake Multi Network Firewall
Mandrake Linux
Mandrake Linux Corporate Server
1 product
Sudo
1 product
Debian Linux
1 product
Secure Linux
1 product
Ubuntu Linux
Configuration A
26 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.2
Todd Miller
Version 1.5.6
Version 1.5.7
Version 1.5.8
Version 1.5.9
Version 1.6.1
Version 1.6.2
Version 1.6.3
Version 1.6.3_p1
Version 1.6.3_p2
Version 1.6.3_p3
Version 1.6.3_p4
Version 1.6.3_p5
Version 1.6.3_p6
Version 1.6.3_p7
Version 1.6.4
Version 1.6.4_p1
Version 1.6.4_p2
Version 1.6.5
Version 1.6.5_p1
Version 1.6.5_p2
Version 1.6.6
Version 1.6.7
Version 1.6.8
Version 1.6.8_p1
Version 1.6
Configuration B
25 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Mandrakesoft
Version 10.0
Version 10.0
Version 10.1
Version 10.1
Version 9.2
Version 9.2
Mandrakesoft
Version 2.1
Version 2.1
Trustix
Version 1.5
Version 2.0
Version 2.1
Version 2.2
Ubuntu
Version 4.1
Version 4.1

References (20)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.