Vulnerabilities > CVE-2004-1689 - Information Disclosure vulnerability in Todd Miller Sudo 1.6.8

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
todd-miller
exploit available

Summary

sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.

Vulnerable Configurations

Part Description Count
Application
Todd_Miller
1

Exploit-Db

descriptionSudoEdit 1.6.8 Local Change Permission Exploit. CVE-2004-1689. Local exploit for linux platform
idEDB-ID:470
last seen2016-01-31
modified2004-09-21
published2004-09-21
reporterAngelo Rosiello
sourcehttps://www.exploit-db.com/download/470/
titleSudoEdit 1.6.8 - Local Change Permission Exploit