// For flags

CVE-2010-0426

sudo: sudoedit option can possibly allow for arbitrary code execution

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.

sudo v1.6.x anterior a v1.6.9p21 y v1.7.x anterior a v1.7.2p4, cuando un pseudo-comando está activado, permite la coincidencia entre el nombre del pseudo-comando y el nombre de un archivo ejecutable en un directorio cualquiera, lo que permite a usuarios locales obtener privilegios a través de un archivo ejecutable manipulado, como se ha demostrado mediante el archivo sudoedit en el directorio home de un usuario.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
Attack Vector
Local
Attack Complexity
Medium
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-01-27 CVE Reserved
  • 2010-02-24 CVE Published
  • 2017-12-16 First Exploit
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (34)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6
Search vendor "Todd Miller" for product "Sudo" and version "1.6"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p3
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p3"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p4
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p4"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p5
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p6
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p6"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.3_p7
Search vendor "Todd Miller" for product "Sudo" and version "1.6.3_p7"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.4_p1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.4_p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.4_p2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.4_p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.5_p1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.5_p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.5_p2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.5_p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.7_p5
Search vendor "Todd Miller" for product "Sudo" and version "1.6.7_p5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.8_p1
Search vendor "Todd Miller" for product "Sudo" and version "1.6.8_p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.8_p2
Search vendor "Todd Miller" for product "Sudo" and version "1.6.8_p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.8_p5
Search vendor "Todd Miller" for product "Sudo" and version "1.6.8_p5"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.8_p7
Search vendor "Todd Miller" for product "Sudo" and version "1.6.8_p7"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.8_p8
Search vendor "Todd Miller" for product "Sudo" and version "1.6.8_p8"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.8_p9
Search vendor "Todd Miller" for product "Sudo" and version "1.6.8_p9"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.8_p12
Search vendor "Todd Miller" for product "Sudo" and version "1.6.8_p12"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.9_p17
Search vendor "Todd Miller" for product "Sudo" and version "1.6.9_p17"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.9_p18
Search vendor "Todd Miller" for product "Sudo" and version "1.6.9_p18"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.6.9_p19
Search vendor "Todd Miller" for product "Sudo" and version "1.6.9_p19"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.0
Search vendor "Todd Miller" for product "Sudo" and version "1.7.0"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.1
Search vendor "Todd Miller" for product "Sudo" and version "1.7.1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.2
Search vendor "Todd Miller" for product "Sudo" and version "1.7.2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.2p1
Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p1"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.2p2
Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p2"
-
Affected
Todd Miller
Search vendor "Todd Miller"
Sudo
Search vendor "Todd Miller" for product "Sudo"
1.7.2p3
Search vendor "Todd Miller" for product "Sudo" and version "1.7.2p3"
-
Affected