CVE-2006-0151
published 2006-01-09CVE-2006-0151: sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a…
PriorityP423high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.61%
45.6th percentile
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.6.8p12-1 (bookworm) | sudo 1.6.8p12-1 (bookworm) |
| sudo_project | sudo | >= 0 < 1.6.8p12-1 | 1.6.8p12-1 |
| sudo_project | sudo | >= 0 < 1.6.8p12-1 | 1.6.8p12-1 |
| sudo_project | sudo | >= 0 < 1.6.8p12-1 | 1.6.8p12-1 |
| sudo_project | sudo | >= 0 < 1.6.8p12-1 | 1.6.8p12-1 |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv4.6MEDIUM
vendor_redhat7.2HIGH
vendor_debian4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7vx7-4r5w-mwxw: sudo 1
ghsa_unreviewed·2022-05-01·CVSS 4.6
CVE-2006-0151 [MEDIUM] GHSA-7vx7-4r5w-mwxw: sudo 1
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
OSV
CVE-2006-0151: sudo 1
osv·2006-01-09·CVSS 4.6
CVE-2006-0151 [MEDIUM] CVE-2006-0151: sudo 1
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
Debian
CVE-2006-0151: sudo - sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment varia...
vendor_debian·2006·CVSS 4.6
CVE-2006-0151 [MEDIUM] CVE-2006-0151: sudo - sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment varia...
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
Scope: local
bookworm: resolved (fixed in 1.6.8p12-1)
bullseye: resolved (fixed in 1.6.8p12-1)
forky: resolved (fixed in 1.6.8p12-1)
sid: resolved (fixed in 1.6.8p12-1)
trixie: resolved (fixed in 1.6.8p12-1)
Red Hat
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
vendor_redhat·2004-11-11·CVSS 7.2
CVE-2004-1051 [HIGH] CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
Statement: We do not consider this to be a security issue:
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=139478#c1
Red Hat
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
vendor_redhat·2004-11-11·CVSS 7.2
CVE-2005-4158 [HIGH] CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script.
Statement: We do not consider this to be a security issue.
https://bugzilla.redhat.com/show_bug.cgi?id=139478#c1
Red Hat
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
vendor_redhat·2004-11-11·CVSS 7.2
CVE-2006-0151 [HIGH] CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
Statement: We do not consider this to be a security issue.
https://bugzilla.redhat.com/show_bug.cgi?id=139478#c1
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9680 sudo: unsafe handling of TZ environment variable
bugzilla·2015-02-10·CVSS 3.3
CVE-2014-9680 [LOW] CVE-2014-9680 sudo: unsafe handling of TZ environment variable
CVE-2014-9680 sudo: unsafe handling of TZ environment variable
sudo 1.8.12 will be released shortly [1] which includes sanity checks for the TZ environment variable.
This issue was previously discussed here:
http://www.openwall.com/lists/oss-security/2014/10/15/24
There is an associated Debian bug:
https://bugs.debian.org/772707
From http://www.sudo.ws/alerts/tz.html
Summary:
Prior to sudo 1.8.12, the TZ environment variable was passed through
unchecked. Most libc tzset() implementations support passing an
absolute pathname in the time zone to point to an arbitrary,
user-controlled file. This may be used to exploit bugs in the C
library's TZ parser or open files the user would not otherwise have
access to. Arbitrary file access via TZ could also be used in a
denial of service attack
Bugzilla
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
bugzilla·2004-11-16·CVSS 7.2
CVE-2004-1051 [HIGH] CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
CVE-2004-1051 bash scripts run via Sudo can be subverted (CVE-2005-4158, CVE-2006-0151)
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; rv:1.7.3) Gecko/20041020
Firefox/0.10.1
Description of problem:
Please see the URL:
http://www.sudo.ws/sudo/alerts/bash_functions.html
to see proper description.
Version-Release number of selected component (if applicable):
sudo-1.6.7p5
How reproducible:
Always
Steps to Reproduce:
To reproduce please follow the description in the "Details:" part of
the page.
Additional info:
Note that this issue can be easily fixed by upgrading sudo to 1.6.8p2.
Discussion:
This issue is not a proper fix, nor should it pose a security issue
for users of sudo.
The fundamental purpose behind sudo is to give trusted users the
ability to perform cert
http://secunia.com/advisories/18358http://secunia.com/advisories/18363http://secunia.com/advisories/18549http://secunia.com/advisories/18558http://secunia.com/advisories/18906http://secunia.com/advisories/19016http://secunia.com/advisories/21692http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.421822http://www.debian.org/security/2006/dsa-946http://www.mandriva.com/security/advisories?name=MDKSA-2006:159http://www.novell.com/linux/security/advisories/2006_02_sr.htmlhttp://www.securityfocus.com/bid/16184http://www.trustix.org/errata/2006/0010https://usn.ubuntu.com/235-2/http://secunia.com/advisories/18358http://secunia.com/advisories/18363http://secunia.com/advisories/18549http://secunia.com/advisories/18558http://secunia.com/advisories/18906http://secunia.com/advisories/19016http://secunia.com/advisories/21692http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.421822http://www.debian.org/security/2006/dsa-946http://www.mandriva.com/security/advisories?name=MDKSA-2006:159http://www.novell.com/linux/security/advisories/2006_02_sr.htmlhttp://www.securityfocus.com/bid/16184http://www.trustix.org/errata/2006/0010https://usn.ubuntu.com/235-2/
2006-01-09
Published