Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53284
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 596-1 (sudo)
Summary:The remote host is missing an update to sudo announced via advisory DSA 596-1.;; This VT has been deprecated and merged into the VT 'Debian: Security Advisory (DSA-596)' (OID: 1.3.6.1.4.1.25623.1.0.53283).
Description:Summary:
The remote host is missing an update to sudo announced via advisory DSA 596-1.

This VT has been deprecated and merged into the VT 'Debian: Security Advisory (DSA-596)' (OID: 1.3.6.1.4.1.25623.1.0.53283).

Vulnerability Insight:
Liam Helmer noticed that sudo, a program that provides limited super
user privileges to specific users, does not clean the environment
sufficiently. Bash functions and the CDPATH variable are still passed
through to the program running as privileged user, leaving
possibilities to overload system routines. These vulnerabilities can
only be exploited by users who have been granted limited super user
privileges.

For the stable distribution (woody) these problems have been fixed in
version 1.6.6-1.2.

For the unstable distribution (sid) these problems have been fixed in
version 1.6.8p3.

Solution:
We recommend that you upgrade your sudo package.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-1051
http://lists.apple.com/archives/security-announce/2005/May/msg00001.html
BugTraq ID: 11668
http://www.securityfocus.com/bid/11668
Bugtraq: 20041112 Sudo version 1.6.8p2 now available (fwd) (Google Search)
http://marc.info/?l=bugtraq&m=110028877431192&w=2
Debian Security Information: DSA-596 (Google Search)
http://www.debian.org/security/2004/dsa-596
http://www.mandriva.com/security/advisories?name=MDKSA-2004:133
http://marc.info/?l=bugtraq&m=110598298225675&w=2
http://www.trustix.org/errata/2004/0061/
https://www.ubuntu.com/usn/usn-28-1/
XForce ISS Database: sudo-bash-command-execution(18055)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18055
CopyrightCopyright (C) 2008 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.