vendor:
sudo
by:
Angelo Rosiello
4.3
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: sudo
Affected Version From: 1.6.2008
Affected Version To: 1.6.2008
Patch Exists: NO
Related CWE: -
CPE: a:sudo:sudo:1.6.8
Platforms Tested:
2004
Sudo Information Disclosure Vulnerability
Sudo is prone to an information disclosure vulnerability. This vulnerability presents itself when sudo is called with the '-e' option, or the 'sudoedit' command is invoked. In certain circumstances, attackers may access the contents of arbitrary files with superuser privileges.
Mitigation:
Update to a version of sudo that is not vulnerable to this issue.