CVE-2002-0043

sudo <1.6.3p7 - Privilege Escalation

Title source: llm

Description

sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain root privileges by modifying environment variables and changing how the mail program is invoked.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Charles Stevenson · bashlocallinux
https://www.exploit-db.com/exploits/21227

Scores

EPSS 0.0019
EPSS Percentile 41.1%

Details

Status published
Products (11)
todd_miller/sudo 1.6
todd_miller/sudo 1.6.1
todd_miller/sudo 1.6.2
todd_miller/sudo 1.6.3
todd_miller/sudo 1.6.3_p1
todd_miller/sudo 1.6.3_p2
todd_miller/sudo 1.6.3_p3
todd_miller/sudo 1.6.3_p4
todd_miller/sudo 1.6.3_p5
todd_miller/sudo 1.6.3_p6
... and 1 more
Published Jan 31, 2002
Tracked Since Feb 18, 2026