HIGH · 7.2

CVE-2004-1051

sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is...

Vulnerability Description

sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MandrakesoftMandrake Multi Network Firewall8.2
Todd MillerSudo1.5.6
DebianDebian Linux3.0
MandrakesoftMandrake Linux9.2
MandrakesoftMandrake Linux Corporate Server2.1
TrustixSecure Linux1.5
UbuntuUbuntu Linux4.1

References

FAQ

What is CVE-2004-1051?

CVE-2004-1051 is a vulnerability with a CVSS score of 7.2 (HIGH). sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is...

How severe is CVE-2004-1051?

CVE-2004-1051 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-1051?

Check the references section above for vendor advisories and patch information. Affected products include: Mandrakesoft Mandrake Multi Network Firewall, Todd Miller Sudo, Debian Debian Linux, Mandrakesoft Mandrake Linux, Mandrakesoft Mandrake Linux Corporate Server.