CVE
- Id
- 4437
- CVE No.
- CVE-2002-0043
- Status
- Entry
- Description
- sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain root privileges by modifying environment variables and changing how the mail program is invoked.
- Phase
- Votes
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
21411 | 4437 | CVE-2002-0043 | BUGTRAQ:20020114 Sudo version 1.6.4 now available (fwd) | View |
21412 | 4437 | CVE-2002-0043 | URL:http://www.securityfocus.com/archive/1/250168 | View |
21413 | 4437 | CVE-2002-0043 | REDHAT:RHSA-2002:013 | View |
21414 | 4437 | CVE-2002-0043 | URL:http://www.redhat.com/support/errata/RHSA-2002-013.html | View |
21415 | 4437 | CVE-2002-0043 | REDHAT:RHSA-2002:011 | View |
21416 | 4437 | CVE-2002-0043 | URL:http://www.redhat.com/support/errata/RHSA-2002-011.html | View |
21417 | 4437 | CVE-2002-0043 | CONECTIVA:CLA-2002:451 | View |
21418 | 4437 | CVE-2002-0043 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000451 | View |
21419 | 4437 | CVE-2002-0043 | ENGARDE:ESA-20020114-001 | View |
21420 | 4437 | CVE-2002-0043 | SUSE:SuSE-SA:2002:002 | View |
21421 | 4437 | CVE-2002-0043 | URL:http://www.novell.com/linux/security/advisories/2002_002_sudo_txt.html | View |
21422 | 4437 | CVE-2002-0043 | MANDRAKE:MDKSA-2002:003 | View |
21423 | 4437 | CVE-2002-0043 | URL:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:003 | View |
21424 | 4437 | CVE-2002-0043 | DEBIAN:DSA-101 | View |
21425 | 4437 | CVE-2002-0043 | URL:http://www.debian.org/security/2002/dsa-101 | View |
21426 | 4437 | CVE-2002-0043 | IMMUNIX:IMNX-2002-70-001-01 | View |
21427 | 4437 | CVE-2002-0043 | URL:http://www.securityfocus.com/advisories/3800 | View |
21428 | 4437 | CVE-2002-0043 | FREEBSD:FreeBSD-SA-02:06 | View |
21429 | 4437 | CVE-2002-0043 | URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02%3A06.asc | View |
21430 | 4437 | CVE-2002-0043 | BUGTRAQ:20020116 Sudo +Postfix Exploit | View |
21431 | 4437 | CVE-2002-0043 | URL:http://marc.info/?l=bugtraq&m=101120193627756&w=2 | View |
21432 | 4437 | CVE-2002-0043 | MISC:http://www.sudo.ws/sudo/alerts/postfix.html | View |
21433 | 4437 | CVE-2002-0043 | XF:sudo-unclean-env-root(7891) | View |
21434 | 4437 | CVE-2002-0043 | URL:http://xforce.iss.net/static/7891.php | View |
21435 | 4437 | CVE-2002-0043 | BID:3871 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
63686 | JVNDB-2002-000013 | Red Hat Linux の sudo における root 権限を取得される脆弱性 | Red Hat Linux に含まれている sudo プログラムにおいて、環境変数の取り扱いの実装に不備があるため、 mail プログラムへ任意のパラメータを渡すことが可能な脆弱性が存在します。 | CVE-2002-0043 | 4437 | 7.2 | http://jvndb.jvn.jp/ja/contents/2002/JVNDB-2002-000013.html | View |