cbcvebase.
CVE-2004-1051
published 2005-03-01

CVE-2004-1051: sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as…

high7.2CVSS 3.1
AVLACLAuNCCICAC
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiansudo< sudo 1.6.8p3-1 (bookworm)sudo 1.6.8p3-1 (bookworm)
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux_corporate_server
mandrakesoftmandrake_multi_network_firewall
sudo_projectsudo>= 0 < 1.6.8p3-11.6.8p3-1
sudo_projectsudo>= 0 < 1.6.8p3-11.6.8p3-1
sudo_projectsudo>= 0 < 1.6.8p3-11.6.8p3-1
sudo_projectsudo>= 0 < 1.6.8p3-11.6.8p3-1
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo

CVSS provenance

nvd7.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH