CVE-2014-0106

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.6 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:S/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
applemac_os_x
𝑥
≤ 10.10.4
todd_millersudo
1.6.9
todd_millersudo
1.6.9p20:p20
todd_millersudo
1.6.9p21:p21
todd_millersudo
1.6.9p22:p22
todd_millersudo
1.6.9p23:p23
todd_millersudo
1.7.0
todd_millersudo
1.7.1
todd_millersudo
1.7.2
todd_millersudo
1.7.2p1:p1
todd_millersudo
1.7.2p2:p2
todd_millersudo
1.7.2p3:p3
todd_millersudo
1.7.2p4:p4
todd_millersudo
1.7.2p5:p5
todd_millersudo
1.7.2p6:p6
todd_millersudo
1.7.2p7:p7
todd_millersudo
1.7.3b1:b1
todd_millersudo
1.7.4
todd_millersudo
1.7.4p1:p1
todd_millersudo
1.7.4p2:p2
todd_millersudo
1.7.4p3:p3
todd_millersudo
1.7.4p4:p4
todd_millersudo
1.7.4p5:p5
todd_millersudo
1.7.4p6:p6
todd_millersudo
1.7.5
todd_millersudo
1.7.6
todd_millersudo
1.7.6p1:p1
todd_millersudo
1.7.6p2:p2
todd_millersudo
1.7.7
todd_millersudo
1.7.8
todd_millersudo
1.7.8p1:p1
todd_millersudo
1.7.8p2:p2
todd_millersudo
1.7.9
todd_millersudo
1.7.9p1:p1
todd_millersudo
1.7.10
todd_millersudo
1.7.10p1:p1
todd_millersudo
1.7.10p2:p2
todd_millersudo
1.7.10p3:p3
todd_millersudo
1.7.10p4:p4
todd_millersudo
1.7.10p5:p5
todd_millersudo
1.7.10p6:p6
todd_millersudo
1.7.10p7:p7
todd_millersudo
1.7.10p8:p8
todd_millersudo
1.7.10p9:p9
todd_millersudo
1.7.10p10:p10
todd_millersudo
1.8.0
todd_millersudo
1.8.1
todd_millersudo
1.8.1p1:p1
todd_millersudo
1.8.1p2:p2
todd_millersudo
1.8.2
todd_millersudo
1.8.3
todd_millersudo
1.8.3p1:p1
todd_millersudo
1.8.3p2:p2
todd_millersudo
1.8.4
todd_millersudo
1.8.4p1:p1
todd_millersudo
1.8.4p2:p2
todd_millersudo
1.8.4p3:p3
todd_millersudo
1.8.4p4:p4
todd_millersudo
1.8.4p5:p5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sudo
bullseye (security)
1.9.5p2-3+deb11u1
fixed
bullseye
1.9.5p2-3+deb11u1
fixed
squeeze
no-dsa
bookworm
1.9.13p3-1+deb12u1
fixed
sid
1.9.16-2
fixed
trixie
1.9.16-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sudo
saucy
not-affected
quantal
not-affected
precise
Fixed 1.8.3p1-1ubuntu3.6
released
lucid
Fixed 1.7.2p1-1ubuntu5.7
released