← Back

CVE-2010-1646

nvd nist
Published: Jun 7, 2010Modified: Apr 29, 2026

JSON object

Loading...
6.2
Vector
AV:L/AC:H/Au:N/C:C/I:C/A:C
Exploitability: 1.9 / Impact: 10.0
Source: NVD

Description

The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.

Affected (74)

Products: Todd Miller: Sudo
1 product
Sudo
Configuration A
74 vulnerable
Vulnerable SoftwareAffected Versions
Todd Miller
Version 1.3.1
Version 1.6.1
Version 1.6.2
Version 1.6.2p1
Version 1.6.2p2
Version 1.6.2p3
Version 1.6.3
Version 1.6.3p1
Version 1.6.3p2
Version 1.6.3p3
Version 1.6.3p4
Version 1.6.3p5
Version 1.6.3p6
Version 1.6.3p7
Version 1.6.4
Version 1.6.4p1
Version 1.6.4p2
Version 1.6.5
Version 1.6.5p1
Version 1.6.5p2
Version 1.6.6
Version 1.6.7
Version 1.6.7p1
Version 1.6.7p2
Version 1.6.7p3
Version 1.6.7p4
Version 1.6.7p5
Version 1.6.8
Version 1.6.8p10
Version 1.6.8p11
Version 1.6.8p12
Version 1.6.8p1
Version 1.6.8p2
Version 1.6.8p3
Version 1.6.8p4
Version 1.6.8p5
Version 1.6.8p6
Version 1.6.8p7
Version 1.6.8p8
Version 1.6.8p9
Version 1.6.9
Version 1.6.9p10
Version 1.6.9p11
Version 1.6.9p12
Version 1.6.9p13
Version 1.6.9p14
Version 1.6.9p15
Version 1.6.9p16
Version 1.6.9p17
Version 1.6.9p18
Version 1.6.9p19
Version 1.6.9p1
Version 1.6.9p20
Version 1.6.9p21
Version 1.6.9p22
Version 1.6.9p2
Version 1.6.9p3
Version 1.6.9p4
Version 1.6.9p5
Version 1.6.9p6
Version 1.6.9p7
Version 1.6.9p8
Version 1.6.9p9
Version 1.6
Version 1.7.0
Version 1.7.1
Version 1.7.2
Version 1.7.2p1
Version 1.7.2p2
Version 1.7.2p3
Version 1.7.2p4
Version 1.7.2p5
Version 1.7.2p6
Version 1.7.2p7

Related CWEs

References (58)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
ExploitPatch
Source: secalert@redhat.com
ExploitPatch
Source: secalert@redhat.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.