CVE-2004-1689
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.
- Affected products
- Sudo
- Todd Miller Sudo
- = 1.6.8
- Fix
- Available
- CVSS 2.0
- 2.1 LOW
- EPSS
- 1.2% (64th percentile)
- NVD status
- Modified
- Published
- 2005-02-20
CVE-2004-1689 at NVD
1 known exploit for CVE-2004-1689
Proof-of-concept code and exploit modules indexed by Sploitus