First published: Sat Apr 16 2005(Updated: )
Sudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary files via a symlink attack on temporary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sudo | =1.5.6 | |
Sudo | =1.5.7 | |
Sudo | =1.5.8 | |
Sudo | =1.5.9 | |
Sudo | =1.6 | |
Sudo | =1.6.1 | |
Sudo | =1.6.2 | |
Sudo | =1.6.3 | |
Sudo | =1.6.3_p1 | |
Sudo | =1.6.3_p2 | |
Sudo | =1.6.3_p3 | |
Sudo | =1.6.3_p4 | |
Sudo | =1.6.3_p5 | |
Sudo | =1.6.3_p6 | |
Sudo | =1.6.3_p7 | |
Sudo | =1.6.4 | |
Sudo | =1.6.4_p1 | |
Sudo | =1.6.4_p2 | |
Sudo | =1.6.5 | |
Sudo | =1.6.5_p1 | |
Sudo | =1.6.5_p2 | |
Sudo | =1.6.6 | |
Sudo | =1.6.7 | |
Sudo | =1.6.7_p5 | |
Sudo | =1.6.8 | |
Sudo | =1.6.8_p1 | |
Sudo | =1.6.8_p8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1119 is classified as a moderate severity vulnerability.
To fix CVE-2005-1119, upgrade to a version of Sudo later than 1.6.8.
CVE-2005-1119 is caused by a symlink attack that allows local users to manipulate temporary files.
Versions of Sudo 1.6.8 and earlier, including 1.5.6 through 1.6.8, are affected by CVE-2005-1119.
CVE-2005-1119 cannot be exploited remotely as it requires local user access to the system.