vulnerability

FreeBSD: VID-2e8cdd36-c3cc-11e5-b5fe-002590263bf5 (CVE-2015-5602): sudo -- potential privilege escalation via symlink misconfiguration

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Jan 26, 2016
Added
Dec 10, 2025
Modified
Dec 10, 2025

Description

MITRE reports: sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt."

Solution

freebsd-upgrade-package-sudo
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.