CVE-2002-0184: Buffer Overflow
Published May 16, 2002
·Updated
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.
Affected Software
2 affected components
Sudo Project Sudo<1.6.6
Debian Debian Linux=2.2
Remediation
Patch Available
Patch Available
Event History
May 16, 2002
CVE Published
via NVD·04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0184?
CVE-2002-0184 is considered a critical vulnerability due to its potential to allow local users to gain root privileges.
2
How do I fix CVE-2002-0184?
To fix CVE-2002-0184, upgrade to Sudo version 1.6.6 or later.
3
Which versions of Sudo are affected by CVE-2002-0184?
CVE-2002-0184 affects all versions of Sudo prior to 1.6.6.
4
Is CVE-2002-0184 specific to any operating systems?
CVE-2002-0184 is noted to affect Debian GNU/Linux 2.2 and other systems using vulnerable versions of Sudo.
5
What type of vulnerability is CVE-2002-0184?
CVE-2002-0184 is an off-by-one error that leads to a heap-based buffer overflow.