First published: Thu Sep 16 2004(Updated: )
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sudo | =1.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1689 has a medium severity rating due to its potential for local privilege escalation.
To fix CVE-2004-1689, upgrade to a later version of sudo that mitigates the symlink attack vector.
Local users operating under the affected version of sudo (1.6.8) can exploit CVE-2004-1689.
CVE-2004-1689 is associated with a symlink attack that can lead to unauthorized file access.
CVE-2004-1689 was discovered in 2004, highlighting a vulnerability in sudo version 1.6.8.