CVE-2014-0106
published 2014-03-11CVE-2014-0106: Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users…
PriorityP419medium6.6CVSS 2.0
AVLACMAuSCCICAC
EPSS
0.34%
26.0th percentile
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.4 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | sudo | < sudo 1.8.5p2-1 (bookworm) | sudo 1.8.5p2-1 (bookworm) |
| sudo_project | sudo | >= 0 < 1.8.5p2-1 | 1.8.5p2-1 |
| sudo_project | sudo | >= 0 < 1.8.5p2-1 | 1.8.5p2-1 |
| sudo_project | sudo | >= 0 < 1.8.5p2-1 | 1.8.5p2-1 |
| sudo_project | sudo | >= 0 < 1.8.5p2-1 | 1.8.5p2-1 |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
CVSS provenance
nvdv2.06.6MEDIUMAV:L/AC:M/Au:S/C:C/I:C/A:C
osv6.6MEDIUM
vendor_debian6.6LOW
vendor_redhat6.6MEDIUM
vendor_ubuntu6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cxvm-3g7g-7vv7: Sudo 1
ghsa_unreviewed·2022-05-17
CVE-2014-0106 [MEDIUM] CWE-20 GHSA-cxvm-3g7g-7vv7: Sudo 1
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.
OSV
CVE-2014-0106: Sudo 1
osv·2014-03-11·CVSS 6.6
CVE-2014-0106 [MEDIUM] CVE-2014-0106: Sudo 1
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.
Ubuntu
Sudo vulnerabilities
vendor_ubuntu·2014-03-13·CVSS 6.6
CVE-2014-0106 [MEDIUM] Sudo vulnerabilities
Title: Sudo vulnerabilities
Summary: Several security issues were fixed in Sudo.
Sebastien Macke discovered that Sudo incorrectly filtered environment
variables when the env_reset option was disabled. A local attacker could
use this issue to possibly run unintended commands by using environment
variables that were intended to be blocked. In a default Ubuntu
installation, the env_reset option is enabled by default. This issue only
affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS. (CVE-2014-0106)
It was discovered that the Sudo init script set a date in the past on
existing timestamp files instead of using epoch to invalidate them
completely. A local attacker could possibly modify the system time to
attempt to reuse timestamp files. This issue only applied to Ubuntu
12.04 LTS, Ubuntu 12.10
Red Hat
sudo: certain environment variables not sanitized when env_reset is disabled
vendor_redhat·2014-03-06·CVSS 6.6
CVE-2014-0106 [MEDIUM] sudo: certain environment variables not sanitized when env_reset is disabled
sudo: certain environment variables not sanitized when env_reset is disabled
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.
Statement: This issue did not affect the version of sudo package as shipped with Red Hat Enterprise Linux 6.
Package: sudo (Red Hat Enterprise Linux 6) - Not affected
Package: sudo (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-0106: sudo - Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check env...
vendor_debian·2014·CVSS 6.6
CVE-2014-0106 [MEDIUM] CVE-2014-0106: sudo - Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check env...
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.
Scope: local
bookworm: resolved (fixed in 1.8.5p2-1)
bullseye: resolved (fixed in 1.8.5p2-1)
forky: resolved (fixed in 1.8.5p2-1)
sid: resolved (fixed in 1.8.5p2-1)
trixie: resolved (fixed in 1.8.5p2-1)
Apple
CVE-2014-0106: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 6.6
CVE-2014-0106 [MEDIUM] CVE-2014-0106: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2014-0106
Component: CVE-2014-0106
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0266.htmlhttp://www.openwall.com/lists/oss-security/2014/03/06/2http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/65997http://www.sudo.ws/sudo/alerts/env_add.htmlhttp://www.ubuntu.com/usn/USN-2146-1https://support.apple.com/kb/HT205031http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0266.htmlhttp://www.openwall.com/lists/oss-security/2014/03/06/2http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/65997http://www.sudo.ws/sudo/alerts/env_add.htmlhttp://www.ubuntu.com/usn/USN-2146-1https://support.apple.com/kb/HT205031
2014-03-11
Published