header-logo
Suggest Exploit
vendor:
Sudo
by:
Slouching and kingcope

Tod Miller Sudo local root exploit

This exploit allows a local user to gain root privileges by exploiting a vulnerability in Sudo versions 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4. The exploit creates a malicious script in the /tmp directory and uses the sudo command to execute it with root privileges. The malicious script contains commands to spawn a root shell.

Mitigation:

Upgrade to Sudo version 1.6.9p21 or 1.7.2p4 or later.
Source

Exploit-DB raw data: