CVE-2004-1689
sudo <1.6.8 - Info Disclosure
Title source: llmDescription
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Angelo Rosiello · clocallinux
https://www.exploit-db.com/exploits/470
References (9)
Scores
EPSS
0.0017
EPSS Percentile
37.5%
Details
Status
published
Products (1)
todd_miller/sudo
1.6.8
Published
Sep 16, 2004
Tracked Since
Feb 18, 2026