Back

MEDIUM

Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are

Published Oct 25, 2005

Description

Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.

Affected products

Remediation

Red Hat statement

We do not consider this to be a security issue: http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=139478#c1

Metrics

Weaknesses (1)

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner debian
Published Oct 25, 2005
Updated Aug 7, 2024
Reserved Sep 19, 2005
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a