20010222 Sudo version 1.6.3p6 now available (fwd)mailing list
http://archives.neohapsis.com/archives/bugtraq/2001-02/0414.html CVE-2001-0279
Sudo 1.5/1.6 - Heap Corruption
Record summary
CVE-2001-0279 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSudo 1.5/1.6 - Heap CorruptionExploitDB exploitby MaXXNot analyzed1 file
References
920010226 Trustix Security Advisory - sudomailing list
http://archives.neohapsis.com/archives/bugtraq/2001-02/0427.html 20010225 [slackware-security] buffer overflow in sudo fixedmailing list
http://archives.neohapsis.com/archives/bugtraq/2001-02/0437.html CLA-2001:381Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000381 DSA-031Vendor advisory
http://www.debian.org/security/2001/dsa-031 MDKSA-2001:024Vendor advisory
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-024.php3 RHSA-2001:018Vendor advisory
http://www.redhat.com/support/errata/RHSA-2001-018.html RHSA-2001:019Vendor advisory
http://www.redhat.com/support/errata/RHSA-2001-019.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0279