CVE-2004-1689
published 2004-09-16CVE-2004-1689: sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the…
PriorityP417low2.1CVSS 2.0
AVLACLAuNCPINAN
EXPLOIT
EPSS
1.17%
63.8th percentile
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.6.8p3-1 (bookworm) | sudo 1.6.8p3-1 (bookworm) |
| sudo_project | sudo | >= 0 < 1.6.8p3-1 | 1.6.8p3-1 |
| sudo_project | sudo | >= 0 < 1.6.8p3-1 | 1.6.8p3-1 |
| sudo_project | sudo | >= 0 < 1.6.8p3-1 | 1.6.8p3-1 |
| sudo_project | sudo | >= 0 < 1.6.8p3-1 | 1.6.8p3-1 |
| todd_miller | sudo | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-53qq-7f4q-p4vg: sudoedit (aka sudo -e) in sudo 1
ghsa_unreviewed·2022-04-29
CVE-2004-1689 [LOW] GHSA-53qq-7f4q-p4vg: sudoedit (aka sudo -e) in sudo 1
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.
OSV
CVE-2004-1689: sudoedit (aka sudo -e) in sudo 1
osv·2004-09-16·CVSS 2.1
CVE-2004-1689 [LOW] CVE-2004-1689: sudoedit (aka sudo -e) in sudo 1
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.
Debian
CVE-2004-1689: sudo - sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges...
vendor_debian·2004·CVSS 2.1
CVE-2004-1689 [LOW] CVE-2004-1689: sudo - sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges...
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.
Scope: local
bookworm: resolved (fixed in 1.6.8p3-1)
bullseye: resolved (fixed in 1.6.8p3-1)
forky: resolved (fixed in 1.6.8p3-1)
sid: resolved (fixed in 1.6.8p3-1)
trixie: resolved (fixed in 1.6.8p3-1)
No detection rules found.
Exploit-DB
Symantec Norton Internet Security 2004 - ActiveX Control Buffer Overflow (Metasploit)
exploitdb·2010-05-09
CVE-2007-1689 Symantec Norton Internet Security 2004 - ActiveX Control Buffer Overflow (Metasploit)
Symantec Norton Internet Security 2004 - ActiveX Control Buffer Overflow (Metasploit)
---
##
# $Id: nis2004_get.rb 9262 2010-05-09 17:45:00Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Symantec Norton Internet Security 2004 ActiveX Control Buffer Overflow',
'Description' => %q{
This module exploits a stack buffer overflow in the ISAlertDataCOM ActiveX
Control (ISLAert.dll) provided by Symantec Norton Internet Security 2004.
By sending a overly long string to the "Get()" method, an attacker may be
able to execute arbitrary code.
Exploit-DB
SudoEdit 1.6.8 - Local Change Permission
exploitdb·2004-09-21
CVE-2004-1689 SudoEdit 1.6.8 - Local Change Permission
SudoEdit 1.6.8 - Local Change Permission
---
/*
Copyright © Rosiello Security 2004
http://www.rosiello.org
sudoedit Exploit
SOFTWARE : sudoedit
REFERENCE: http://www.sudo.ws/sudo/alerts/sudoedit.html
DATE: 18/09/2004
Summary:
A flaw in exists in sudo's -u option (aka sudoedit)
in sudo version 1.6.8 that can give an attacker
read permission to a file that would otherwise be
unreadable.
Sudo versions affected:
1.6.8 only
Credit:
Reznic Valery discovered the problem.
All the information that you can find in this software
were published for educational and didactic purpose only.
The author published this program under the condition
that is not in the intention of the reader to use them
in order to bring to himself or others a profit or to bring
to others damage.
!Respect the law!
http://marc.info/?l=bugtraq&m=109537972929201&w=2http://packetstormsecurity.nl/0409-exploits/sudoedit.txthttp://secunia.com/advisories/12596http://www.ciac.org/ciac/bulletins/o-219.shtmlhttp://www.kb.cert.org/vuls/id/424358http://www.osvdb.org/10023http://www.securityfocus.com/bid/11204http://www.sudo.ws/sudo/alerts/sudoedit.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/17424http://marc.info/?l=bugtraq&m=109537972929201&w=2http://packetstormsecurity.nl/0409-exploits/sudoedit.txthttp://secunia.com/advisories/12596http://www.ciac.org/ciac/bulletins/o-219.shtmlhttp://www.kb.cert.org/vuls/id/424358http://www.osvdb.org/10023http://www.securityfocus.com/bid/11204http://www.sudo.ws/sudo/alerts/sudoedit.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/17424
2004-09-16
Published