vendor:
Sudo
by:
breno
7.5
CVSS
HIGH
Security-bypass
CWE
Product Name: Sudo
Affected Version From: < 1.6.8p12
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Sudo security-bypass vulnerability
The vulnerability allows a local attacker with the ability to run Python scripts to gain access to an interactive Python prompt and execute arbitrary code with elevated privileges.
Mitigation:
Upgrade to a version of Sudo that is not affected by this vulnerability.