CVE-2010-1163
The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.
- Todd Miller Sudo
- = 1.6.8, 1.6.8_p1, 1.6.8_p2, 1.6.8_p5, 1.6.8_p7, 1.6.8_p8, 1.6.8_p9, 1.6.8_p12, 1.6.8p7, 1.6.9_p17, 1.6.9_p18, 1.6.9_p19, 1.6.9_p20, 1.6.9_p21, 1.6.9_p22, 1.7.0, 1.7.1, 1.7.2p1, 1.7.2p2, 1.7.2p3, 1.7.2p4
- Fix
- Available
- CVSS 2.0
- 6.9 MEDIUM
- EPSS
- 0.4% (33th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2010-04-16
CVE-2010-1163 at NVD
2 known exploits for CVE-2010-1163
Proof-of-concept code and exploit modules indexed by Sploitus