First published: Thu May 16 2002(Updated: )
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sudo Project Sudo | <1.6.6 | |
Debian GNU/Linux | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0184 is considered a critical vulnerability due to its potential to allow local users to gain root privileges.
To fix CVE-2002-0184, upgrade to Sudo version 1.6.6 or later.
CVE-2002-0184 affects all versions of Sudo prior to 1.6.6.
CVE-2002-0184 is noted to affect Debian GNU/Linux 2.2 and other systems using vulnerable versions of Sudo.
CVE-2002-0184 is an off-by-one error that leads to a heap-based buffer overflow.