Back

MEDIUM

sudo: sudoedit option can possibly allow for arbitrary code execution

Published Feb 24, 2010

Description

sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.

Affected products

Remediation

Red Hat statement

It did not affect the versions of the sudo package as shipped with Red Hat Enterprise Linux 3 and 4.

Metrics

Weaknesses (1)

References (33)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 24, 2010
Updated Aug 7, 2024
Reserved Jan 27, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Feb 21, 2010