sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade sudo | Dec 1, 2016 | Feb 24, 2010 |
| Debian | — | Upgrade sudo | Jul 30, 2024 | Feb 24, 2010 |
| Freebsd | — | Upgrade sudo | Dec 10, 2025 | Mar 1, 2010 |
| Gentoo Linux | — | Upgrade app-admin/sudo. | Oct 30, 2017 | Feb 24, 2010 |
| Oracle_linux | — | Upgrade sudo | Oct 16, 2024 | Feb 24, 2010 |
| Suse | — | Upgrade sudoUpgrade sap-aio-release | Feb 17, 2015 | Feb 24, 2010 |
| Ubuntu | — | Upgrade sudo-ldapUpgrade sudo | Nov 8, 2024 | Feb 24, 2010 |
| Vmsa 2010 0009 1 Service Console Package Sudo | — | Upgrade VMware ESX 4.0 to build number 256968 | Sep 2, 2010 | Feb 24, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub