Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2010-1163

The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.4%
CVSS Severity
CVSS v2 Score 6.9
References
Products affected by CVE-2010-1163
  • Todd Miller » Sudo » Version: 1.6.8
    cpe:2.3:a:todd_miller:sudo:1.6.8
  • Todd Miller » Sudo » Version: 1.6.8_p1
    cpe:2.3:a:todd_miller:sudo:1.6.8_p1
  • Todd Miller » Sudo » Version: 1.6.8_p12
    cpe:2.3:a:todd_miller:sudo:1.6.8_p12
  • Todd Miller » Sudo » Version: 1.6.8_p2
    cpe:2.3:a:todd_miller:sudo:1.6.8_p2
  • Todd Miller » Sudo » Version: 1.6.8_p5
    cpe:2.3:a:todd_miller:sudo:1.6.8_p5
  • Todd Miller » Sudo » Version: 1.6.8_p7
    cpe:2.3:a:todd_miller:sudo:1.6.8_p7
  • Todd Miller » Sudo » Version: 1.6.8_p8
    cpe:2.3:a:todd_miller:sudo:1.6.8_p8
  • Todd Miller » Sudo » Version: 1.6.8_p9
    cpe:2.3:a:todd_miller:sudo:1.6.8_p9
  • Todd Miller » Sudo » Version: 1.6.8p7
    cpe:2.3:a:todd_miller:sudo:1.6.8p7
  • Todd Miller » Sudo » Version: 1.6.9_p17
    cpe:2.3:a:todd_miller:sudo:1.6.9_p17
  • Todd Miller » Sudo » Version: 1.6.9_p18
    cpe:2.3:a:todd_miller:sudo:1.6.9_p18
  • Todd Miller » Sudo » Version: 1.6.9_p19
    cpe:2.3:a:todd_miller:sudo:1.6.9_p19
  • Todd Miller » Sudo » Version: 1.6.9_p20
    cpe:2.3:a:todd_miller:sudo:1.6.9_p20
  • Todd Miller » Sudo » Version: 1.6.9_p21
    cpe:2.3:a:todd_miller:sudo:1.6.9_p21
  • Todd Miller » Sudo » Version: 1.6.9_p22
    cpe:2.3:a:todd_miller:sudo:1.6.9_p22
  • Todd Miller » Sudo » Version: 1.7.0
    cpe:2.3:a:todd_miller:sudo:1.7.0
  • Todd Miller » Sudo » Version: 1.7.1
    cpe:2.3:a:todd_miller:sudo:1.7.1
  • Todd Miller » Sudo » Version: 1.7.2p1
    cpe:2.3:a:todd_miller:sudo:1.7.2p1
  • Todd Miller » Sudo » Version: 1.7.2p2
    cpe:2.3:a:todd_miller:sudo:1.7.2p2
  • Todd Miller » Sudo » Version: 1.7.2p3
    cpe:2.3:a:todd_miller:sudo:1.7.2p3
  • Todd Miller » Sudo » Version: 1.7.2p4
    cpe:2.3:a:todd_miller:sudo:1.7.2p4


Contact Us

Shodan ® - All rights reserved