// For flags

CVE-2005-2959

 

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2005-09-19 CVE Reserved
  • 2005-10-25 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6
Search vendor "Todd Miller" for product "Sudo" and version "1.6"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p3
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p4
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p5
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p6
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p6"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p7
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p7"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3p1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3p2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3p3
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3p3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3p4
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3p4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3p5
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3p5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3p6
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3p6"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3p7
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3p7"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.4
Search vendor "Todd Miller" for product "Sudo" and version "1.6.4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.4_p1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.4_p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.4_p2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.4_p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.4p1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.4p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.4p2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.4p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.5
Search vendor "Todd Miller" for product "Sudo" and version "1.6.5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.5_p1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.5_p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.5_p2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.5_p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.5p1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.5p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.5p2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.5p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.6
Search vendor "Todd Miller" for product "Sudo" and version "1.6.6"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.7
Search vendor "Todd Miller" for product "Sudo" and version "1.6.7"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.7_p5
Search vendor "Todd Miller" for product "Sudo" and version "1.6.7_p5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.8
Search vendor "Todd Miller" for product "Sudo" and version "1.6.8"
-
Affected