2.1
CVSSv2

CVE-2004-1689

Published: 16/09/2004 Updated: 11/07/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.

Vulnerable Product Search on Vulmon Subscribe to Product

todd miller sudo 1.6.8

Exploits

/* Copyright © Rosiello Security 2004 wwwrosielloorg sudoedit Exploit SOFTWARE : sudoedit REFERENCE: wwwsudows/sudo/alerts/sudoedithtml DATE: 18/09/2004 Summary: A flaw in exists in sudo's -u option (aka sudoedit) in sudo version 168 that can give an attacker read permission to a fil ...