CVE-2004-1689

sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.
Configurations

Configuration 1 (hide)

cpe:2.3:a:todd_miller:sudo:1.6.8:*:*:*:*:*:*:*

History

No history.

Information

Published : 2004-09-16 04:00

Updated : 2017-07-11 01:31


NVD link : CVE-2004-1689

Mitre link : CVE-2004-1689

CVE.ORG link : CVE-2004-1689


JSON object : View

Products Affected

todd_miller

  • sudo