First published: Thu Sep 16 2004(Updated: )
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Todd Miller Sudo | =1.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.