CVE-2010-1646
published 2010-06-07CVE-2010-1646: The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH…
PriorityP420medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.46%
37.1th percentile
The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.7.2p7-1 (bookworm) | sudo 1.7.2p7-1 (bookworm) |
| sudo_project | sudo | >= 0 < 1.7.2p7-1 | 1.7.2p7-1 |
| sudo_project | sudo | >= 0 < 1.7.2p7-1 | 1.7.2p7-1 |
| sudo_project | sudo | >= 0 < 1.7.2p7-1 | 1.7.2p7-1 |
| sudo_project | sudo | >= 0 < 1.7.2p7-1 | 1.7.2p7-1 |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xww5-hh94-wcq9: The secure path feature in env
ghsa_unreviewed·2022-05-14
CVE-2010-1646 [MEDIUM] GHSA-xww5-hh94-wcq9: The secure path feature in env
The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.
OSV
CVE-2010-1646: The secure path feature in env
osv·2010-06-07·CVSS 6.2
CVE-2010-1646 [MEDIUM] CVE-2010-1646: The secure path feature in env
The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.
Ubuntu
sudo vulnerability
vendor_ubuntu·2010-06-30
CVE-2010-1646 sudo vulnerability
Title: sudo vulnerability
Summary: Under certain conditions, a user might be able to run commands with
administrative privileges.
Evan Broder and Anders Kaseorg discovered that sudo did not properly
sanitize its environment when configured to use secure_path (the default in
Ubuntu). A local attacker could exploit this to execute arbitrary code as
root if sudo was configured to allow the attacker to use a program that
interpreted the PATH environment variable.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
sudo: insufficient environment sanitization issue
vendor_redhat·2010-05-28·CVSS 6.2
CVE-2010-1646 [MEDIUM] sudo: insufficient environment sanitization issue
sudo: insufficient environment sanitization issue
The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.
Debian
CVE-2010-1646: sudo - The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 throug...
vendor_debian·2010·CVSS 6.2
CVE-2010-1646 [MEDIUM] CVE-2010-1646: sudo - The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 throug...
The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.
Scope: local
bookworm: resolved (fixed in 1.7.2p7-1)
bullseye: resolved (fixed in 1.7.2p7-1)
forky: resolved (fixed in 1.7.2p7-1)
sid: resolved (fixed in 1.7.2p7-1)
trixie: resolved (fixed in 1.7.2p7-1)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042838.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/043012.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/043026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40002http://secunia.com/advisories/40188http://secunia.com/advisories/40215http://secunia.com/advisories/40508http://secunia.com/advisories/43068http://security.gentoo.org/glsa/glsa-201009-03.xmlhttp://wiki.rpath.com/Advisories:rPSA-2010-0075http://www.debian.org/security/2010/dsa-2062http://www.mandriva.com/security/advisories?name=MDVSA-2010:118http://www.osvdb.org/65083http://www.redhat.com/support/errata/RHSA-2010-0475.htmlhttp://www.securityfocus.com/archive/1/514489/100/0/threadedhttp://www.securityfocus.com/bid/40538http://www.securitytracker.com/id?1024101http://www.sudo.ws/repos/sudo/rev/3057fde43cf0http://www.sudo.ws/repos/sudo/rev/a09c6812eaechttp://www.sudo.ws/sudo/alerts/secure_path.htmlhttp://www.vupen.com/english/advisories/2010/1452http://www.vupen.com/english/advisories/2010/1478http://www.vupen.com/english/advisories/2010/1518http://www.vupen.com/english/advisories/2010/1519http://www.vupen.com/english/advisories/2011/0212https://bugzilla.redhat.com/show_bug.cgi?id=598154https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10580https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7338http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042838.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/043012.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/043026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40002http://secunia.com/advisories/40188http://secunia.com/advisories/40215http://secunia.com/advisories/40508http://secunia.com/advisories/43068http://security.gentoo.org/glsa/glsa-201009-03.xmlhttp://wiki.rpath.com/Advisories:rPSA-2010-0075http://www.debian.org/security/2010/dsa-2062http://www.mandriva.com/security/advisories?name=MDVSA-2010:118http://www.osvdb.org/65083http://www.redhat.com/support/errata/RHSA-2010-0475.htmlhttp://www.securityfocus.com/archive/1/514489/100/0/threadedhttp://www.securityfocus.com/bid/40538http://www.securitytracker.com/id?1024101http://www.sudo.ws/repos/sudo/rev/3057fde43cf0http://www.sudo.ws/repos/sudo/rev/a09c6812eaechttp://www.sudo.ws/sudo/alerts/secure_path.htmlhttp://www.vupen.com/english/advisories/2010/1452http://www.vupen.com/english/advisories/2010/1478http://www.vupen.com/english/advisories/2010/1518http://www.vupen.com/english/advisories/2010/1519http://www.vupen.com/english/advisories/2011/0212https://bugzilla.redhat.com/show_bug.cgi?id=598154https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10580https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7338
2010-06-07
Published