Vulnerability Name: | CVE-2005-1993 (CCN-21080) | ||||||||||||||||||||||||
Assigned: | 2005-06-20 | ||||||||||||||||||||||||
Published: | 2005-06-20 | ||||||||||||||||||||||||
Updated: | 2018-10-19 | ||||||||||||||||||||||||
Summary: | Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack. | ||||||||||||||||||||||||
CVSS v3 Severity: | 4.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 3.7 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2005-1993 Source: CCN Type: Conectiva Linux Announcement CLSA-2005:976 Sudo - Local vulnerability Source: APPLE Type: UNKNOWN APPLE-SA-2005-11-29 Source: CCN Type: RHSA-2005-535 sudo security update Source: CCN Type: SA15744 Sudo Arbitrary Command Execution Vulnerability Source: SECUNIA Type: UNKNOWN 15744 Source: CCN Type: SA17813 Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 17813 Source: DEBIAN Type: UNKNOWN DSA-735 Source: DEBIAN Type: DSA-735 sudo -- pathname validation race Source: CCN Type: GLSA-200506-22 sudo: Arbitrary command execution Source: SUSE Type: UNKNOWN SUSE-SA:2005:036 Source: CCN Type: OpenPKG-SA-2005.012 sudo Source: OSVDB Type: UNKNOWN 17396 Source: CCN Type: OSVDB ID: 17396 Sudo sudoers ALL Entry Race Condition Source: REDHAT Type: UNKNOWN RHSA-2005:535 Source: BUGTRAQ Type: Patch, Vendor Advisory 20050620 Sudo version 1.6.8p9 now available, fixes security issue. Source: FEDORA Type: UNKNOWN FLSA:162750 Source: BID Type: UNKNOWN 13993 Source: CCN Type: BID-13993 Todd Miller Sudo Local Race Condition Vulnerability Source: BID Type: UNKNOWN 15647 Source: CCN Type: BID-15647 RETIRED: Apple Mac OS X Security Update 2005-009 Multiple Vulnerabilities Source: CCN Type: Sudo Web site Race condition in Sudo's pathname validation Source: CONFIRM Type: UNKNOWN http://www.sudo.ws/sudo/alerts/path_race.html Source: CCN Type: Sudo Download Web page Downloading Sudo Source: CCN Type: TLSA-2005-73 Symlink attack in sudo Source: CCN Type: USN-142-1 sudo vulnerability Source: VUPEN Type: UNKNOWN ADV-2005-0821 Source: VUPEN Type: UNKNOWN ADV-2005-2659 Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161116 Source: XF Type: UNKNOWN sudo-pathname-race-condition(21080) Source: XF Type: UNKNOWN sudo-pathname-race-condition(21080) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11341 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1242 Source: SUSE Type: SUSE-SA:2005:036 sudo: race condition arbitrary code execution | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |