CVE-2005-4158
Summary
| CVE | CVE-2005-4158 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-11 02:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Todd Miller | Sudo | 1.5.6 | All | All | All |
| Application | Todd Miller | Sudo | 1.5.7 | All | All | All |
| Application | Todd Miller | Sudo | 1.5.8 | All | All | All |
| Application | Todd Miller | Sudo | 1.5.9 | All | All | All |
| Application | Todd Miller | Sudo | 1.6 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.1 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.2 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.3 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.3_p1 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.3_p2 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.3_p3 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.3_p4 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.3_p5 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.3_p6 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.3_p7 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.4 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.4_p1 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.4_p2 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.5 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.5_p1 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.5_p2 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.6 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.7 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.7_p5 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.8 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.8_p1 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.8_p5 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.8_p7 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.8_p8 | All | All | All |
| Application | Todd Miller | Sudo | 1.6.8_p9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| usn/usn-235-1 - Ubuntu Linux | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Perl scripts run via Sudo can be subverted | af854a3a-2127-422b-91ae-364da2661108 | www.sudo.ws | Patch, Vendor Advisory |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Debian -- Security Information -- DSA-946-2 sudo | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| www.trustix.org/errata/2006/0002 | af854a3a-2127-422b-91ae-364da2661108 | www.trustix.org | |
| Secunia - Advisories - Mandriva update for sudo | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Secunia - Advisories - Fedora update for sudo | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian update for sudo - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Secunia - Advisories - Sudo Perl Environment Cleaning Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Mandriva update for sudo - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SUSE update for multiple packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityTracker.com Archives - Sudo Input Validation Flaw in Perl-related Environment Variables Lets Certain Local Users Execute Arbitrary Perl Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch |
| Trustix update for multiple packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Sudo Perl Environment Variable Handling Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| Secunia - Advisories - Ubuntu update for sudo | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-01-24 | Mark J Cox | We do not consider this to be a security issue. http:bugzilla.redhat.combugzillashow_bug.cgi?id=139478#c1 |
There are currently no legacy QID mappings associated with this CVE.