cbcvebase.
CVE-2004-1051
published 2005-03-01

CVE-2004-1051: sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as…

PriorityP425high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
1.37%
69.1th percentile
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiansudo< sudo 1.6.8p3-1 (bookworm)sudo 1.6.8p3-1 (bookworm)
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux_corporate_server
mandrakesoftmandrake_multi_network_firewall
sudo_projectsudo>= 0 < 1.6.8p3-11.6.8p3-1
sudo_projectsudo>= 0 < 1.6.8p3-11.6.8p3-1
sudo_projectsudo>= 0 < 1.6.8p3-11.6.8p3-1
sudo_projectsudo>= 0 < 1.6.8p3-11.6.8p3-1
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.