Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GratiSoft Sudo 受限命令执行绕过漏洞
Vulnerability Description
本地用户可以借助sudo 1.6.8p2之前版本,利用"()"样式环境变量创建与BASH脚本中任何程序同名的函数(即未使用程序的完整路径名),来执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A