Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sudo sudoedit路径解析本地权限提升漏洞
Vulnerability Description
Sudo是软件开发者Todd C. Miller所研发的一套用于类Unix操作系统下并允许用户通过安全的方式使用特殊的权限执行命令的程序。 Sudo命令匹配功能存在本地权限提升漏洞,在当前工作目录下的某个文件与sudoers文件伪命令重名,且PATH包含"."符输入时,无法进行正确处理。本地用户可使用sudoedit,通过可执行木马程序执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A