CVE-2004-1689

sudo 1.6.8 - Arbitrary File Read via sudoedit Symlink Attack

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1689. PoCs published by Angelo Rosiello.

AI-analyzed exploit summary This exploit leverages a race condition in sudoedit (sudo 1.6.8) to create a symlink to a target file (e.g., /etc/shadow) while sudoedit is running, allowing unauthorized read access. The attacker must execute the exploit while the victim has sudoedit open on a specific file.

Description

sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Angelo Rosiello · clocallinux
https://www.exploit-db.com/exploits/470

This exploit leverages a race condition in sudoedit (sudo 1.6.8) to create a symlink to a target file (e.g., /etc/shadow) while sudoedit is running, allowing unauthorized read access. The attacker must execute the exploit while the victim has sudoedit open on a specific file.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Racy
Target: sudo 1.6.8
Auth required
Prerequisites: sudoedit must be running on a file named 'rosiello' · Attacker must have write access to /usr/tmp
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12596
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=109537972929201&w=2
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/424358
Patch, Vendor Advisory vdb-entry x_refsource_osvdb
http://www.osvdb.org/10023
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11204
Patch, Vendor Advisory third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/o-219.shtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17424
Patch, Vendor Advisory x_refsource_confirm
http://www.sudo.ws/sudo/alerts/sudoedit.html
Patch, Vendor Advisory x_refsource_misc
http://packetstormsecurity.nl/0409-exploits/sudoedit.txt

Scores

EPSS 0.0117
EPSS Percentile 63.2%

Details

Status published
Products (1)
todd_miller/sudo 1.6.8
Published Sep 16, 2004
Tracked Since Feb 18, 2026