CVE-2004-1051
published 2005-03-01CVE-2004-1051: sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as…
PriorityP425high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
1.37%
69.1th percentile
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | sudo | < sudo 1.6.8p3-1 (bookworm) | sudo 1.6.8p3-1 (bookworm) |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux_corporate_server | — | — |
| mandrakesoft | mandrake_multi_network_firewall | — | — |
| sudo_project | sudo | >= 0 < 1.6.8p3-1 | 1.6.8p3-1 |
| sudo_project | sudo | >= 0 < 1.6.8p3-1 | 1.6.8p3-1 |
| sudo_project | sudo | >= 0 < 1.6.8p3-1 | 1.6.8p3-1 |
| sudo_project | sudo | >= 0 < 1.6.8p3-1 | 1.6.8p3-1 |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-792w-v225-x939: sudo before 1
ghsa_unreviewed·2022-04-29
CVE-2004-1051 [HIGH] GHSA-792w-v225-x939: sudo before 1
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
OSV
CVE-2004-1051: sudo before 1
osv·2005-03-01·CVSS 7.2
CVE-2004-1051 [HIGH] CVE-2004-1051: sudo before 1
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
Red Hat
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
vendor_redhat·2004-11-11·CVSS 7.2
CVE-2004-1051 [HIGH] CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
Statement: We do not consider this to be a security issue:
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=139478#c1
Red Hat
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
vendor_redhat·2004-11-11·CVSS 7.2
CVE-2005-4158 [HIGH] CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script.
Statement: We do not consider this to be a security issue.
https://bugzilla.redhat.com/show_bug.cgi?id=139478#c1
Red Hat
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
vendor_redhat·2004-11-11·CVSS 7.2
CVE-2006-0151 [HIGH] CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
Statement: We do not consider this to be a security issue.
https://bugzilla.redhat.com/show_bug.cgi?id=139478#c1
Debian
CVE-2004-1051: sudo - sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "(...
vendor_debian·2004·CVSS 7.2
CVE-2004-1051 [HIGH] CVE-2004-1051: sudo - sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "(...
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
Scope: local
bookworm: resolved (fixed in 1.6.8p3-1)
bullseye: resolved (fixed in 1.6.8p3-1)
forky: resolved (fixed in 1.6.8p3-1)
sid: resolved (fixed in 1.6.8p3-1)
trixie: resolved (fixed in 1.6.8p3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9680 sudo: unsafe handling of TZ environment variable
bugzilla·2015-02-10·CVSS 3.3
CVE-2014-9680 [LOW] CVE-2014-9680 sudo: unsafe handling of TZ environment variable
CVE-2014-9680 sudo: unsafe handling of TZ environment variable
sudo 1.8.12 will be released shortly [1] which includes sanity checks for the TZ environment variable.
This issue was previously discussed here:
http://www.openwall.com/lists/oss-security/2014/10/15/24
There is an associated Debian bug:
https://bugs.debian.org/772707
From http://www.sudo.ws/alerts/tz.html
Summary:
Prior to sudo 1.8.12, the TZ environment variable was passed through
unchecked. Most libc tzset() implementations support passing an
absolute pathname in the time zone to point to an arbitrary,
user-controlled file. This may be used to exploit bugs in the C
library's TZ parser or open files the user would not otherwise have
access to. Arbitrary file access via TZ could also be used in a
denial of service attack
Bugzilla
missing sudo update for CVE 2004-1051
bugzilla·2005-08-04
[MEDIUM] missing sudo update for CVE 2004-1051
missing sudo update for CVE 2004-1051
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.8) Gecko/20050523
Description of problem:
The bug described above was fixed for fc1 and older distributions y the fedora legacy project and in fc3 by the fedora project. It seems there is no fix package for fc2.
A flaw in exists in sudo's environment sanitizing prior to sudo
version 1.6.8p2 that could allow a malicious user with permission to
run a shell script that utilized the bash shell to run arbitrary
commands. The /bin/sh shell on most (if not all) Linux systems is bash.
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=139671
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=139478
http://www.sudo.ws/sudo/alerts/bash_functions.html
Version-Release numbe
Bugzilla
CAN-2004-1051, CAN-2004-1689, CAN-2005-1119, CAN-2005-1831, CAN-2005-1993 sudo issues
bugzilla·2005-07-08·CVSS 2.1
[LOW] CAN-2004-1051, CAN-2004-1689, CAN-2005-1119, CAN-2005-1831, CAN-2005-1993 sudo issues
CAN-2004-1051, CAN-2004-1689, CAN-2005-1119, CAN-2005-1831, CAN-2005-1993 sudo issues
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.8) Gecko/20050513 Fedora/1.0.4-1.3.1 Firefox/1.0.4
Description of problem:
http://www.courtesan.com/sudo/alerts/path_race.html describes a problem with sudo that as far as I know hasn't been fixed in fedora legacy.
Version-Release number of selected component (if applicable):
How reproducible:
Didn't try
Additional info:
Discussion:
CAN-2004-1689 sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with
root privileges, which allows local users to read arbitrary files via a symlink
attack on the temporary file before quitting sudoedit.
CAN-2005-1119 Sudo VISudo 1.6.8 and earlier allows local users to corrupt
Bugzilla
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
bugzilla·2004-11-16·CVSS 7.2
CVE-2004-1051 [HIGH] CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; rv:1.7.3) Gecko/20041020
Firefox/0.10.1
Description of problem:
Please see the URL:
http://www.sudo.ws/sudo/alerts/bash_functions.html
to see proper description.
Version-Release number of selected component (if applicable):
sudo-1.6.7p5
How reproducible:
Always
Steps to Reproduce:
To reproduce please follow the description in the "Details:" part of
the page.
Additional info:
Note that this issue can be easily fixed by upgrading sudo to 1.6.8p2.
Discussion:
This issue is not a proper fix, nor should it pose a security issue
for users of sudo.
The fundamental purpose behind sudo is to give trusted users the
ability to perform cert
http://lists.apple.com/archives/security-announce/2005/May/msg00001.htmlhttp://marc.info/?l=bugtraq&m=110028877431192&w=2http://marc.info/?l=bugtraq&m=110598298225675&w=2http://www.debian.org/security/2004/dsa-596http://www.mandriva.com/security/advisories?name=MDKSA-2004:133http://www.securityfocus.com/bid/11668http://www.sudo.ws/sudo/alerts/bash_functions.htmlhttp://www.trustix.org/errata/2004/0061/https://exchange.xforce.ibmcloud.com/vulnerabilities/18055https://www.ubuntu.com/usn/usn-28-1/http://lists.apple.com/archives/security-announce/2005/May/msg00001.htmlhttp://marc.info/?l=bugtraq&m=110028877431192&w=2http://marc.info/?l=bugtraq&m=110598298225675&w=2http://www.debian.org/security/2004/dsa-596http://www.mandriva.com/security/advisories?name=MDKSA-2004:133http://www.securityfocus.com/bid/11668http://www.sudo.ws/sudo/alerts/bash_functions.htmlhttp://www.trustix.org/errata/2004/0061/https://exchange.xforce.ibmcloud.com/vulnerabilities/18055https://www.ubuntu.com/usn/usn-28-1/
2005-03-01
Published