Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2004-1051
Description:sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
Test IDs: 1.3.6.1.4.1.25623.1.0.53283   1.3.6.1.4.1.25623.1.0.52302   1.3.6.1.4.1.25623.1.0.52833   1.3.6.1.4.1.25623.1.0.53284   1.3.6.1.4.1.25623.1.0.52696  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2004-1051
http://lists.apple.com/archives/security-announce/2005/May/msg00001.html
BugTraq ID: 11668
http://www.securityfocus.com/bid/11668
Bugtraq: 20041112 Sudo version 1.6.8p2 now available (fwd) (Google Search)
http://marc.info/?l=bugtraq&m=110028877431192&w=2
Debian Security Information: DSA-596 (Google Search)
http://www.debian.org/security/2004/dsa-596
http://www.mandriva.com/security/advisories?name=MDKSA-2004:133
http://marc.info/?l=bugtraq&m=110598298225675&w=2
http://www.trustix.org/errata/2004/0061/
https://www.ubuntu.com/usn/usn-28-1/
XForce ISS Database: sudo-bash-command-execution(18055)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18055




© 1998-2025 E-Soft Inc. All rights reserved.