V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2015-5602
DEB
MediumConfirmedExploit available

sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multip…

CVSS
6.8
Medium
EPSS
0.06
p90
Published
2015-01-01
Updated
2015-01-01
Description

sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt."

Tags · CWE
CWE-264
CWE-59
CAPEC-17
CAPEC-35
CAPEC-76
CAPEC-132
Affected products
Sudo ≤ 1.8.14
CVSS vector
AV:N/AC:H/Au:S/C:C/I:C/A:P
Timeline
2015-01-01
Published
2015-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Authentication
Au: S
Single
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.055 · p90
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-35 · CWE-59
└ via CAPEC-35 · CWE-59
└ via CAPEC-132 · CWE-59
└ via CAPEC-35 · CWE-59
Known exploits — Сканер-ВС
37710
exploitdb · https://www.exploit-db.com/exploits/37710
Enterprise
CVE-2015-5602
github-poc · https://github.com/cved-sources/cve-2015-5602
Enterprise
Affected software
ProductVendorStatus
sudoTracked
sudoTracked
sudoTracked
sudoTracked
sudoTracked
sudoTracked
sudoTracked
sudoTracked
sudoTracked
sudoTracked
sudoTracked
sudoTracked
sudoTracked
sudo*Tracked
Source databases
DEB
CVE
UBU