CVE-2002-0043: High severity Todd Miller Sudo vulnerability
Published Jan 31, 2002
·Updated
sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain root privileges by modifying environment variables and changing how the mail program is invoked.
Affected Software
11 affected components
Todd Miller Sudo=1.6.3_p6
Todd Miller Sudo=1.6.3
Todd Miller Sudo=1.6.1
Todd Miller Sudo=1.6.3_p5
Todd Miller Sudo=1.6.2
Todd Miller Sudo=1.6.3_p2
Todd Miller Sudo=1.6.3_p4
Todd Miller Sudo=1.6.3_p3
Todd Miller Sudo=1.6.3_p7
Todd Miller Sudo=1.6
Todd Miller Sudo=1.6.3_p1
Remediation
Patch Available
Event History
Jan 31, 2002
CVE Published
05:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0043?
CVE-2002-0043 has a high severity rating due to its potential to allow local users to gain root privileges.
2
How do I fix CVE-2002-0043?
To fix CVE-2002-0043, update to a patched version of sudo that is higher than 1.6.3p7.
3
Which versions of sudo are affected by CVE-2002-0043?
CVE-2002-0043 affects sudo versions from 1.6.0 to 1.6.3p7.
4
Can CVE-2002-0043 be exploited remotely?
No, CVE-2002-0043 can only be exploited by local users who have access to the system.
5
What are the implications of CVE-2002-0043 for system security?
CVE-2002-0043 poses a significant security risk as it could allow unauthorized users to execute commands with root privileges.