← Back

CVE-2010-0426

nvd nist
Published: Feb 24, 2010Modified: Apr 29, 2026

JSON object

Loading...
6.9
Vector
AV:L/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 3.4 / Impact: 10.0
Source: NVD

Description

sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.

Affected (32)

Products: Todd Miller: Sudo
1 product
Sudo
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Todd Miller
Version 1.6.1
Version 1.6.2
Version 1.6.3
Version 1.6.3_p1
Version 1.6.3_p2
Version 1.6.3_p3
Version 1.6.3_p4
Version 1.6.3_p5
Version 1.6.3_p6
Version 1.6.3_p7
Version 1.6.4_p1
Version 1.6.4_p2
Version 1.6.5_p1
Version 1.6.5_p2
Version 1.6.7_p5
Version 1.6.8_p12
Version 1.6.8_p1
Version 1.6.8_p2
Version 1.6.8_p5
Version 1.6.8_p7
Version 1.6.8_p8
Version 1.6.8_p9
Version 1.6.9_p17
Version 1.6.9_p18
Version 1.6.9_p19
Version 1.6
Version 1.7.0
Version 1.7.1
Version 1.7.2
Version 1.7.2p1
Version 1.7.2p2
Version 1.7.2p3

Related CWEs

References (58)

ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gz (unsafe URL)
Source: secalert@redhat.com
Patch
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Patch
Source: secalert@redhat.com
Patch
Source: secalert@redhat.com
Source: secalert@redhat.com
Vendor Advisory
ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gz (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.