Vulnerability Name: | CVE-2004-1689 (CCN-17424) | ||||||||
Assigned: | 2004-09-16 | ||||||||
Published: | 2004-09-16 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Sep 16 2004 - 14:23:21 CDT [sudo-announce] Sudo version 1.6.8p1 now available (fwd) Source: MITRE Type: CNA CVE-2004-1689 Source: BUGTRAQ Type: UNKNOWN 20040916 [sudo-announce] Sudo version 1.6.8p1 now available (fwd) Source: MISC Type: Patch, Vendor Advisory http://packetstormsecurity.nl/0409-exploits/sudoedit.txt Source: CCN Type: SA12596 sudo Arbitrary File Reading Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 12596 Source: CCN Type: CIAC Information Bulletin 0-219 Sudo - "Sudoedit" Vulnerabilities Source: CIAC Type: Patch, Vendor Advisory O-219 Source: CCN Type: US-CERT VU#424358 sudoedit can expose protected file contents Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#424358 Source: OSVDB Type: Patch, Vendor Advisory 10023 Source: CCN Type: OSVDB ID: 10023 sudo sudoedit Restricted Local File Disclosure Source: BID Type: Exploit, Patch, Vendor Advisory 11204 Source: CCN Type: BID-11204 Sudo Information Disclosure Vulnerability Source: CCN Type: Sudo Web site Sudo Main Page Source: CCN Type: Sudo Security Alert September 15, 2004 Sudoedit can expose file contents Source: CONFIRM Type: Patch, Vendor Advisory http://www.sudo.ws/sudo/alerts/sudoedit.html Source: XF Type: UNKNOWN sudo-sudoedit-view-files(17424) Source: XF Type: UNKNOWN sudo-sudoedit-view-files(17424) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |