VYPR
Unrated severityNVD Advisory· Published Feb 24, 2010· Updated Apr 29, 2026

CVE-2010-0426

CVE-2010-0426

Description

sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.

Affected products

32
  • Todd Miller/Sudo32 versions
    cpe:2.3:a:todd_miller:sudo:1.6.9_p19:*:*:*:*:*:*:*+ 31 more
    • cpe:2.3:a:todd_miller:sudo:1.6.9_p19:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.7.2p1:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.3_p1:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.3_p2:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.3_p3:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.3_p4:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.3_p5:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.3_p6:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.3_p7:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.4_p1:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.4_p2:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.5_p1:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.5_p2:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.7_p5:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.8_p1:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.8_p2:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.8_p5:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.8_p7:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.8_p8:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.8_p9:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.8_p12:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.9_p17:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.6.9_p18:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.7.2p2:*:*:*:*:*:*:*
    • cpe:2.3:a:todd_miller:sudo:1.7.2p3:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

29

News mentions

0

No linked articles in our index yet.