Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-0426

EPSS 0.76% · P73
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-0426

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Sudo sudoedit命令本地权限提升漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Sudo是一款允许用户以其他用户权限安全地执行命令的程序,广泛使用在Linux和Unix操作系统下。 sudoedit命令权限提升漏洞,拥有sudoedit权限的本地用户可以以root用户权限执行任意代码。成功攻击要求sudoedit命令没有在sudoers文件中指定完整路径。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-0426

#POC DescriptionSource LinkShenlong Link
1Sudo 1.6.x <= 1.6.9p21 and 1.7.x <= 1.7.2p4 Local Privilege Escalation and vulnerable containerhttps://github.com/t0kx/privesc-CVE-2010-0426POC Details
2cve-2010-0426https://github.com/cved-sources/cve-2010-0426POC Details
3sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4 - Privilege escalation with sudo and sudoedithttps://github.com/g1vi/CVE-2010-0426POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-0426

登录查看更多情报信息。

Same Patch Batch · n/a · 2010-02-24 · 6 CVEs total

CVE-2010-0285gnome屏幕保护程序X配置安全跳过漏洞
CVE-2010-0420Pidgin 多个拒绝服务攻击漏洞
CVE-2010-0422gnome屏幕保护程序安全绕过漏洞
CVE-2010-0423Pidgin ‘gtkimhtml.c’拒绝服务漏洞
CVE-2010-0640CA eHealth Performance Manager Web界面跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2010-0426

No comments yet


Leave a comment