CVE-2005-4158
published 2005-12-11CVE-2005-4158: Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows…
PriorityP420medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EXPLOIT
EPSS
1.08%
61.5th percentile
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.6.8p12-1 (bookworm) | sudo 1.6.8p12-1 (bookworm) |
| sudo_project | sudo | >= 0 < 1.6.8p12-1 | 1.6.8p12-1 |
| sudo_project | sudo | >= 0 < 1.6.8p12-1 | 1.6.8p12-1 |
| sudo_project | sudo | >= 0 < 1.6.8p12-1 | 1.6.8p12-1 |
| sudo_project | sudo | >= 0 < 1.6.8p12-1 | 1.6.8p12-1 |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_redhat7.2HIGH
vendor_debian4.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h6pw-5prw-wv25: Sudo before 1
ghsa_unreviewed·2022-05-01
CVE-2005-4158 [MEDIUM] GHSA-h6pw-5prw-wv25: Sudo before 1
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script.
GHSA
GHSA-7vx7-4r5w-mwxw: sudo 1
ghsa_unreviewed·2022-05-01·CVSS 4.6
CVE-2006-0151 [MEDIUM] GHSA-7vx7-4r5w-mwxw: sudo 1
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
OSV
CVE-2006-0151: sudo 1
osv·2006-01-09·CVSS 4.6
CVE-2006-0151 [MEDIUM] CVE-2006-0151: sudo 1
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
OSV
CVE-2005-4158: Sudo before 1
osv·2005-12-11·CVSS 4.6
CVE-2005-4158 [MEDIUM] CVE-2005-4158: Sudo before 1
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script.
Ubuntu
sudo vulnerability
vendor_ubuntu·2006-01-09
CVE-2005-4158 sudo vulnerability
Title: sudo vulnerability
Summary: sudo vulnerability
USN-235-1 fixed a vulnerability in sudo's handling of environment
variables. Tavis Ormandy noticed that sudo did not filter out the
PYTHONINSPECT environment variable, so that users with the limited
privilege of calling a python script with sudo could still escalate
their privileges.
For reference, this is the original advisory:
Charles Morris discovered a privilege escalation vulnerability in
sudo. On executing Perl scripts with sudo, various environment
variables that affect Perl's library search path were not cleaned
properly. If sudo is set up to grant limited sudo execution of Perl
scripts to normal users, this could be exploited to run arbitrary
commands as the target user.
This security update also filters out environment va
Ubuntu
sudo vulnerability
vendor_ubuntu·2006-01-06
CVE-2005-4158 sudo vulnerability
Title: sudo vulnerability
Summary: sudo vulnerability
Charles Morris discovered a privilege escalation vulnerability in
sudo. On executing Perl scripts with sudo, various environment
variables that affect Perl's library search path were not cleaned
properly. If sudo is set up to grant limited sudo execution of Perl
scripts to normal users, this could be exploited to run arbitrary
commands as the target user.
This security update also filters out environment variables that can
be exploited similarly with Python, Ruby, and zsh scripts.
Please note that this does not affect the default Ubuntu installation,
or any setup that just grants full root privileges to certain users.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2006-0151: sudo - sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment varia...
vendor_debian·2006·CVSS 4.6
CVE-2006-0151 [MEDIUM] CVE-2006-0151: sudo - sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment varia...
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
Scope: local
bookworm: resolved (fixed in 1.6.8p12-1)
bullseye: resolved (fixed in 1.6.8p12-1)
forky: resolved (fixed in 1.6.8p12-1)
sid: resolved (fixed in 1.6.8p12-1)
trixie: resolved (fixed in 1.6.8p12-1)
Debian
CVE-2005-4158: sudo - Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) P...
vendor_debian·2005·CVSS 4.6
CVE-2005-4158 [MEDIUM] CVE-2005-4158: sudo - Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) P...
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script.
Scope: local
bookworm: resolved (fixed in 1.6.8p12-1)
bullseye: resolved (fixed in 1.6.8p12-1)
forky: resolved (fixed in 1.6.8p12-1)
sid: resolved (fixed in 1.6.8p12-1)
trixie: resolved (fixed in 1.6.8p12-1)
Red Hat
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
vendor_redhat·2004-11-11·CVSS 7.2
CVE-2004-1051 [HIGH] CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
Statement: We do not consider this to be a security issue:
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=139478#c1
Red Hat
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
vendor_redhat·2004-11-11·CVSS 7.2
CVE-2005-4158 [HIGH] CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script.
Statement: We do not consider this to be a security issue.
https://bugzilla.redhat.com/show_bug.cgi?id=139478#c1
Red Hat
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
vendor_redhat·2004-11-11·CVSS 7.2
CVE-2006-0151 [HIGH] CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
Statement: We do not consider this to be a security issue.
https://bugzilla.redhat.com/show_bug.cgi?id=139478#c1
No detection rules found.
Exploit-DB
Sudo 1.6.x - Environment Variable Handling Security Bypass (2)
exploitdb·2006-01-09
CVE-2005-4158 Sudo 1.6.x - Environment Variable Handling Security Bypass (2)
Sudo 1.6.x - Environment Variable Handling Security Bypass (2)
---
source: https://www.securityfocus.com/bid/16184/info
Sudo is prone to a security-bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling environment variables.
A local attacker with the ability to run Python scripts can exploit this vulnerability to gain access to an interactive Python prompt. That attacker may then execute arbitrary code with elevated privileges, facilitating the complete compromise of affected computers.
An attacker must have the ability to run Python scripts through Sudo to exploit this vulnerability.
This issue is similar to BID 15394 (Sudo Perl Environment Variable Handling Security Bypass Vulnerability).
## Sudo local root
Exploit-DB
Sudo 1.6.x - Environment Variable Handling Security Bypass (1)
exploitdb·2006-01-09
CVE-2005-4158 Sudo 1.6.x - Environment Variable Handling Security Bypass (1)
Sudo 1.6.x - Environment Variable Handling Security Bypass (1)
---
source: https://www.securityfocus.com/bid/16184/info
Sudo is prone to a security-bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling environment variables.
A local attacker with the ability to run Python scripts can exploit this vulnerability to gain access to an interactive Python prompt. That attacker may then execute arbitrary code with elevated privileges, facilitating the complete compromise of affected computers.
An attacker must have the ability to run Python scripts through Sudo to exploit this vulnerability.
This issue is similar to BID 15394 (Sudo Perl Environment Variable Handling Security Bypass Vulnerability).
## Sudo local root
Exploit-DB
Sudo Perl 1.6.x - Environment Variable Handling Security Bypass
exploitdb·2005-11-11
CVE-2005-4158 Sudo Perl 1.6.x - Environment Variable Handling Security Bypass
Sudo Perl 1.6.x - Environment Variable Handling Security Bypass
---
source: https://www.securityfocus.com/bid/15394/info
Sudo is prone to a security-bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling the 'PERLLIB', 'PERL5LIB', and 'PERL5OPT' environment variables when tainting is ignored.
An attacker can exploit this vulnerability to bypass security restrictions and include arbitrary library files.
To exploit this vulnerability, an attacker must be able to run Perl scripts through Sudo.
## Sudo local root exploit ##
## vuln versions : sudo mkdir modules
breno ~ $ -> mkdir FTP
breno ~/modules $ -> ls
FTP
breno ~/modules $ -> cd FTP
breno ~/modules/FTP $ -> h2xs -AXc -n FTP
Defaulting to backwards compatibili
Bugzilla
CVE-2014-9680 sudo: unsafe handling of TZ environment variable
bugzilla·2015-02-10·CVSS 3.3
CVE-2014-9680 [LOW] CVE-2014-9680 sudo: unsafe handling of TZ environment variable
CVE-2014-9680 sudo: unsafe handling of TZ environment variable
sudo 1.8.12 will be released shortly [1] which includes sanity checks for the TZ environment variable.
This issue was previously discussed here:
http://www.openwall.com/lists/oss-security/2014/10/15/24
There is an associated Debian bug:
https://bugs.debian.org/772707
From http://www.sudo.ws/alerts/tz.html
Summary:
Prior to sudo 1.8.12, the TZ environment variable was passed through
unchecked. Most libc tzset() implementations support passing an
absolute pathname in the time zone to point to an arbitrary,
user-controlled file. This may be used to exploit bugs in the C
library's TZ parser or open files the user would not otherwise have
access to. Arbitrary file access via TZ could also be used in a
denial of service attack
Bugzilla
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
bugzilla·2004-11-16·CVSS 7.2
CVE-2004-1051 [HIGH] CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; rv:1.7.3) Gecko/20041020
Firefox/0.10.1
Description of problem:
Please see the URL:
http://www.sudo.ws/sudo/alerts/bash_functions.html
to see proper description.
Version-Release number of selected component (if applicable):
sudo-1.6.7p5
How reproducible:
Always
Steps to Reproduce:
To reproduce please follow the description in the "Details:" part of
the page.
Additional info:
Note that this issue can be easily fixed by upgrading sudo to 1.6.8p2.
Discussion:
This issue is not a proper fix, nor should it pose a security issue
for users of sudo.
The fundamental purpose behind sudo is to give trusted users the
ability to perform cert
http://secunia.com/advisories/17534/http://secunia.com/advisories/18102http://secunia.com/advisories/18156http://secunia.com/advisories/18308http://secunia.com/advisories/18463http://secunia.com/advisories/18549http://secunia.com/advisories/18558http://secunia.com/advisories/21692http://securitytracker.com/alerts/2005/Nov/1015192.htmlhttp://www.debian.org/security/2006/dsa-946http://www.mandriva.com/security/advisories?name=MDKSA-2005:234http://www.mandriva.com/security/advisories?name=MDKSA-2006:159http://www.novell.com/linux/security/advisories/2006_02_sr.htmlhttp://www.securityfocus.com/bid/15394http://www.sudo.ws/sudo/alerts/perl_env.htmlhttp://www.trustix.org/errata/2006/0002/http://www.vupen.com/english/advisories/2005/2386https://exchange.xforce.ibmcloud.com/vulnerabilities/23102https://www.ubuntu.com/usn/usn-235-1/http://secunia.com/advisories/17534/http://secunia.com/advisories/18102http://secunia.com/advisories/18156http://secunia.com/advisories/18308http://secunia.com/advisories/18463http://secunia.com/advisories/18549http://secunia.com/advisories/18558http://secunia.com/advisories/21692http://securitytracker.com/alerts/2005/Nov/1015192.htmlhttp://www.debian.org/security/2006/dsa-946http://www.mandriva.com/security/advisories?name=MDKSA-2005:234http://www.mandriva.com/security/advisories?name=MDKSA-2006:159http://www.novell.com/linux/security/advisories/2006_02_sr.htmlhttp://www.securityfocus.com/bid/15394http://www.sudo.ws/sudo/alerts/perl_env.htmlhttp://www.trustix.org/errata/2006/0002/http://www.vupen.com/english/advisories/2005/2386https://exchange.xforce.ibmcloud.com/vulnerabilities/23102https://www.ubuntu.com/usn/usn-235-1/
2005-12-11
Published