NVD

Id
29040  
Name
CVE-2014-0106  
Description
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.  
Reject
 
CVSS Version
2  
CVSS Score
6.6  
Severity
Medium  
CVSS Base Score
6.6  
CVSS Impact Subscore
10  
CVSS Exploit Subscore
2.7  
CVSS Vector
(AV:L/AC:M/Au:S/C:C/I:C/A:C)  
Pub Date
2017-01-19  
Published
2014-03-11  
Modified Date
2016-11-28  
Seq
2014-0106  

Actions