Description
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-160-1 | sudo security update |
EUVD |
EUVD-2014-0185 | Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable. |
Ubuntu USN |
USN-2146-1 | Sudo vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:38.667Z
Reserved: 2013-12-03T00:00:00.000Z
Link: CVE-2014-0106
No data.
Status : Modified
Published: 2014-03-11T19:37:03.240
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-0106
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN