CVE-2005-2959
published 2005-10-25CVE-2005-2959: Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables…
PriorityP416medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.62%
46.0th percentile
Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.6.8p9-3 (bookworm) | sudo 1.6.8p9-3 (bookworm) |
| sudo_project | sudo | >= 0 < 1.6.8p9-3 | 1.6.8p9-3 |
| sudo_project | sudo | >= 0 < 1.6.8p9-3 | 1.6.8p9-3 |
| sudo_project | sudo | >= 0 < 1.6.8p9-3 | 1.6.8p9-3 |
| sudo_project | sudo | >= 0 < 1.6.8p9-3 | 1.6.8p9-3 |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xq6m-vcfr-h89q: Incomplete blacklist vulnerability in sudo 1
ghsa_unreviewed·2022-05-01
CVE-2005-2959 [MEDIUM] GHSA-xq6m-vcfr-h89q: Incomplete blacklist vulnerability in sudo 1
Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.
OSV
CVE-2005-2959: Incomplete blacklist vulnerability in sudo 1
osv·2005-10-25·CVSS 4.6
CVE-2005-2959 [MEDIUM] CVE-2005-2959: Incomplete blacklist vulnerability in sudo 1
Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.
Ubuntu
sudo vulnerability
vendor_ubuntu·2005-10-28
CVE-2005-2959 sudo vulnerability
Title: sudo vulnerability
Summary: sudo vulnerability
Tavis Ormandy discovered a privilege escalation vulnerability in sudo.
On executing shell scripts with sudo, the "P4" and "SHELLOPTS"
environment variables were not cleaned properly. If sudo is set up to
grant limited sudo privileges to normal users this could be exploited
to run arbitrary commands as the target user.
Updated packags for Ubuntu 4.10:
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2005-2959: sudo - Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users ...
vendor_debian·2005·CVSS 4.6
CVE-2005-2959 [MEDIUM] CVE-2005-2959: sudo - Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users ...
Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.
Scope: local
bookworm: resolved (fixed in 1.6.8p9-3)
bullseye: resolved (fixed in 1.6.8p9-3)
forky: resolved (fixed in 1.6.8p9-3)
sid: resolved (fixed in 1.6.8p9-3)
trixie: resolved (fixed in 1.6.8p9-3)
Red Hat
CVE-2005-2959: Incomplete blacklist vulnerability in sudo 1
vendor_redhat·CVSS 4.6
CVE-2005-2959 [MEDIUM] CVE-2005-2959: Incomplete blacklist vulnerability in sudo 1
Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.
Statement: We do not consider this to be a security issue:
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=139478#c1
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://docs.info.apple.com/article.html?artnum=305214http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlhttp://secunia.com/advisories/17318http://secunia.com/advisories/17322http://secunia.com/advisories/17345http://secunia.com/advisories/17390http://secunia.com/advisories/17666http://secunia.com/advisories/18549http://secunia.com/advisories/24479http://www.debian.org/security/2005/dsa-870http://www.mandriva.com/security/advisories?name=MDKSA-2005:201http://www.novell.com/linux/security/advisories/2006_02_sr.htmlhttp://www.openpkg.org/security/OpenPKG-SA-2006.002-sudo.htmlhttp://www.securityfocus.com/advisories/9643http://www.securityfocus.com/bid/15191http://www.sudo.ws/bugs/show_bug.cgi?id=182http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://www.vupen.com/english/advisories/2007/0930https://usn.ubuntu.com/213-1/http://docs.info.apple.com/article.html?artnum=305214http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlhttp://secunia.com/advisories/17318http://secunia.com/advisories/17322http://secunia.com/advisories/17345http://secunia.com/advisories/17390http://secunia.com/advisories/17666http://secunia.com/advisories/18549http://secunia.com/advisories/24479http://www.debian.org/security/2005/dsa-870http://www.mandriva.com/security/advisories?name=MDKSA-2005:201http://www.novell.com/linux/security/advisories/2006_02_sr.htmlhttp://www.openpkg.org/security/OpenPKG-SA-2006.002-sudo.htmlhttp://www.securityfocus.com/advisories/9643http://www.securityfocus.com/bid/15191http://www.sudo.ws/bugs/show_bug.cgi?id=182http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://www.vupen.com/english/advisories/2007/0930https://usn.ubuntu.com/213-1/
2005-10-25
Published