vendor:
sudoedit
by:
Angelo Rosiello
7.5
CVSS
HIGH
Information Disclosure
CWE
Product Name: sudoedit
Affected Version From: 1.6.2008
Affected Version To: 1.6.2008
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2004
sudoedit Exploit
A flaw exists in sudo's -u option (aka sudoedit) in sudo version 1.6.8 that can give an attacker read permission to a file that would otherwise be unreadable.
Mitigation:
Upgrade to a version of sudo that is not affected by this vulnerability.