CVE-2006-0151

sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:todd_miller:sudo:1.5.6:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.5.7:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.5.8:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.5.9:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p1:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p2:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p3:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p4:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p5:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p6:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.3_p7:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.4_p1:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.4_p2:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.5:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.5_p1:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.5_p2:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.6:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.7:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.7_p5:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.8:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.8_p1:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.8_p2:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.8_p5:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.8_p7:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.8_p8:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.8_p9:*:*:*:*:*:*:*
cpe:2.3:a:todd_miller:sudo:1.6.8_p12:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:ubuntu:ubuntu_linux:4.1:*:ia64:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:4.1:*:ppc:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:5.04:*:amd64:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:5.04:*:i386:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:5.04:*:powerpc:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:5.10:*:amd64:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:5.10:*:i386:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:5.10:*:powerpc:*:*:*:*:*

History

21 Nov 2024, 00:05

Type Values Removed Values Added
References () http://secunia.com/advisories/18358 - Vendor Advisory () http://secunia.com/advisories/18358 - Vendor Advisory
References () http://secunia.com/advisories/18363 - Patch, Vendor Advisory () http://secunia.com/advisories/18363 - Patch, Vendor Advisory
References () http://secunia.com/advisories/18549 - () http://secunia.com/advisories/18549 -
References () http://secunia.com/advisories/18558 - () http://secunia.com/advisories/18558 -
References () http://secunia.com/advisories/18906 - () http://secunia.com/advisories/18906 -
References () http://secunia.com/advisories/19016 - () http://secunia.com/advisories/19016 -
References () http://secunia.com/advisories/21692 - () http://secunia.com/advisories/21692 -
References () http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.421822 - () http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.421822 -
References () http://www.debian.org/security/2006/dsa-946 - () http://www.debian.org/security/2006/dsa-946 -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2006:159 - () http://www.mandriva.com/security/advisories?name=MDKSA-2006:159 -
References () http://www.novell.com/linux/security/advisories/2006_02_sr.html - () http://www.novell.com/linux/security/advisories/2006_02_sr.html -
References () http://www.securityfocus.com/bid/16184 - Exploit () http://www.securityfocus.com/bid/16184 - Exploit
References () http://www.trustix.org/errata/2006/0010 - () http://www.trustix.org/errata/2006/0010 -
References () https://usn.ubuntu.com/235-2/ - () https://usn.ubuntu.com/235-2/ -

Information

Published : 2006-01-09 23:03

Updated : 2024-11-21 00:05


NVD link : CVE-2006-0151

Mitre link : CVE-2006-0151

CVE.ORG link : CVE-2006-0151


JSON object : View

Products Affected

todd_miller

  • sudo

ubuntu

  • ubuntu_linux