The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-04-16 12:30
Updated : 2018-10-10 12:55
NVD link : CVE-2010-1163
Mitre link : CVE-2010-1163
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
todd_miller
- sudo