The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.
References
Link Providers
http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042838.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043012.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043026.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html cve-icon cve-icon
http://secunia.com/advisories/40002 cve-icon cve-icon
http://secunia.com/advisories/40188 cve-icon cve-icon
http://secunia.com/advisories/40215 cve-icon cve-icon
http://secunia.com/advisories/40508 cve-icon cve-icon
http://secunia.com/advisories/43068 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-201009-03.xml cve-icon cve-icon
http://wiki.rpath.com/Advisories:rPSA-2010-0075 cve-icon cve-icon
http://www.debian.org/security/2010/dsa-2062 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2010:118 cve-icon cve-icon
http://www.osvdb.org/65083 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2010-0475.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/514489/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/40538 cve-icon cve-icon
http://www.securitytracker.com/id?1024101 cve-icon cve-icon
http://www.sudo.ws/repos/sudo/rev/3057fde43cf0 cve-icon cve-icon
http://www.sudo.ws/repos/sudo/rev/a09c6812eaec cve-icon cve-icon
http://www.sudo.ws/sudo/alerts/secure_path.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1452 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1478 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1518 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1519 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0212 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=598154 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2010-1646 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10580 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7338 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2010-1646 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2010-06-07T14:00:00

Updated: 2024-08-07T01:28:41.583Z

Reserved: 2010-04-29T00:00:00

Link: CVE-2010-1646

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-06-07T17:12:48.123

Modified: 2024-11-21T01:14:52.780

Link: CVE-2010-1646

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-05-28T00:00:00Z

Links: CVE-2010-1646 - Bugzilla