ID | CVE-2014-0106 | ||||||
Sažetak | Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable. | ||||||
Reference |
|
||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:L/AC:M/Au:S/C:C/I:C/A:C | ||||||
Zadnje važnije ažuriranje | 16-12-2017 - 02:29 | ||||||
Objavljeno | 11-03-2014 - 19:37 |