SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-2959

Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other…

MEDIUM 4.6EPSS 0.62%

Does this matter?

Lower severity and a low EPSS score (0.62%). Track it; it rarely justifies an emergency change on its own.

Description

Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.

CVSS 2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
0.62% probability · 48th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
todd miller/sudo
Source
security@debian.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.