CVE-2015-5602
17.11.2015, 15:59
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt."Enginsight
| Vendor | Product | Version |
|---|---|---|
| sudo_project | sudo | 𝑥 ≤ 1.8.14 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References