vendor:
Sudo
by:
breno
7.5
CVSS
HIGH
Security Bypass
CWE
Product Name: Sudo
Affected Version From: Sudo versions prior to 1.6.8p12
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Sudo Security Bypass Vulnerability
Sudo is prone to a security-bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling the 'PERLLIB', 'PERL5LIB', and 'PERL5OPT' environment variables when tainting is ignored. An attacker can exploit this vulnerability to bypass security restrictions and include arbitrary library files.
Mitigation:
Update to Sudo version 1.6.8p12 or later to address this issue.