CVE-2002-0043

sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain root privileges by modifying environment variables and changing how the mail program is invoked.
References
Link Resource
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02%3A06.asc
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000451
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:003
http://marc.info/?l=bugtraq&m=101120193627756&w=2
http://www.debian.org/security/2002/dsa-101
http://www.novell.com/linux/security/advisories/2002_002_sudo_txt.html
http://www.redhat.com/support/errata/RHSA-2002-011.html
http://www.redhat.com/support/errata/RHSA-2002-013.html Patch Vendor Advisory
http://www.securityfocus.com/advisories/3800
http://www.securityfocus.com/archive/1/250168 Vendor Advisory
http://www.securityfocus.com/bid/3871
http://www.sudo.ws/sudo/alerts/postfix.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/7891
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02%3A06.asc
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000451
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:003
http://marc.info/?l=bugtraq&m=101120193627756&w=2
http://www.debian.org/security/2002/dsa-101
http://www.novell.com/linux/security/advisories/2002_002_sudo_txt.html
http://www.redhat.com/support/errata/RHSA-2002-011.html
http://www.redhat.com/support/errata/RHSA-2002-013.html Patch Vendor Advisory
http://www.securityfocus.com/advisories/3800
http://www.securityfocus.com/archive/1/250168 Vendor Advisory
http://www.securityfocus.com/bid/3871
http://www.sudo.ws/sudo/alerts/postfix.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/7891
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:todd_miller:sudo:1.6:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p1:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p2:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p3:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p4:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p5:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p6:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p7:*:*:*:*:*:*:*

History

20 Nov 2024, 23:38

Type Values Removed Values Added
References () ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02%3A06.asc - () ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02%3A06.asc -
References () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000451 - () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000451 -
References () http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:003 - () http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:003 -
References () http://marc.info/?l=bugtraq&m=101120193627756&w=2 - () http://marc.info/?l=bugtraq&m=101120193627756&w=2 -
References () http://www.debian.org/security/2002/dsa-101 - () http://www.debian.org/security/2002/dsa-101 -
References () http://www.novell.com/linux/security/advisories/2002_002_sudo_txt.html - () http://www.novell.com/linux/security/advisories/2002_002_sudo_txt.html -
References () http://www.redhat.com/support/errata/RHSA-2002-011.html - () http://www.redhat.com/support/errata/RHSA-2002-011.html -
References () http://www.redhat.com/support/errata/RHSA-2002-013.html - Patch, Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2002-013.html - Patch, Vendor Advisory
References () http://www.securityfocus.com/advisories/3800 - () http://www.securityfocus.com/advisories/3800 -
References () http://www.securityfocus.com/archive/1/250168 - Vendor Advisory () http://www.securityfocus.com/archive/1/250168 - Vendor Advisory
References () http://www.securityfocus.com/bid/3871 - () http://www.securityfocus.com/bid/3871 -
References () http://www.sudo.ws/sudo/alerts/postfix.html - () http://www.sudo.ws/sudo/alerts/postfix.html -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/7891 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/7891 -

Information

Published : 2002-01-31 05:00

Updated : 2024-11-20 23:38


NVD link : CVE-2002-0043

Mitre link : CVE-2002-0043

CVE.ORG link : CVE-2002-0043


JSON object : View

Products Affected

todd_miller

  • sudo