Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

GratiSoft Sudo Restricted Command Execution Bypass Vulnerability

A restricted command execution bypass vulnerability affects GratiSoft's Sudo application. This issue is due to a design error that causes the application to fail to properly sanitize user-supplied environment variables.

An attacker with sudo privileges may leverage this issue to execute commands that are explicitly disallowed. This may facilitate privileges escalation and certainly leads to a false sense of security.







 

Privacy Statement
Copyright 2008, SecurityFocus