CVE-2004-1689: Low severity Todd Miller Sudo vulnerability
Published Sep 16, 2004
·Updated
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.
Affected Software
1 affected component
Todd Miller Sudo=1.6.8
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Sep 16, 2004
CVE Published
04:00 AM
Feb 20, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1689?
CVE-2004-1689 has a medium severity rating due to its potential for local privilege escalation.
2
How do I fix CVE-2004-1689?
To fix CVE-2004-1689, upgrade to a later version of sudo that mitigates the symlink attack vector.
3
Who is affected by CVE-2004-1689?
Local users operating under the affected version of sudo (1.6.8) can exploit CVE-2004-1689.
4
What type of attack is CVE-2004-1689 associated with?
CVE-2004-1689 is associated with a symlink attack that can lead to unauthorized file access.
5
When was CVE-2004-1689 discovered?
CVE-2004-1689 was discovered in 2004, highlighting a vulnerability in sudo version 1.6.8.