CVE-2002-0184
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.
- Affected products
- Sudo
- Sudo Project Sudo
- < 1.6.6
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 1.2% (65th percentile)
- Weakness
- CWE-131
- NVD status
- Modified
- Published
- 2003-04-02
CVE-2002-0184 at NVD
1 known exploit for CVE-2002-0184
Proof-of-concept code and exploit modules indexed by Sploitus