Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Sudo | — | Apply OS X security update 2007-003Upgrade macOS to the latest version | Dec 16, 2011 | Oct 25, 2005 |
| Debian | — | Upgrade sudo | Jul 30, 2024 | Oct 25, 2005 |
| Freebsd | — | Upgrade sudo | Dec 10, 2025 | Feb 16, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub