7.2
CVSSv2

CVE-1999-0958

Published: 12/01/1998 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.

Vulnerable Product Search on Vulmon Subscribe to Product

todd miller sudo 1.5.2

todd miller sudo 1.5.3

todd miller sudo 1.5

Github Repositories

A docker image containing a vulnerable version of sudo. Intended for use as a CTF challenge.

Sudo CTF Challenge Challenge Name: Sudotdot Prompt: You've just landed a job at //best/software/inc Congratulations! However, now that you're working here, you found out their security policies are quite oppressive They're enforced using this old version of sudo I wonder if you can find a way around it? Description of Vulnerability This challenge takes adv