CVE

Id
10117  
CVE No.
CVE-2004-1689  
Status
Candidate  
Description
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.  
Phase
Assigned (20050221)  
Votes
None (candidate not yet proposed)  
Comments