CVE-2015-5602
Publication date 17 November 2015
Last updated 24 July 2024
Ubuntu priority
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt."
Status
Package | Ubuntu Release | Status |
---|---|---|
sudo | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Ignored | |
Notes
mdeslaur
Backporting the fix for this issue is risky, may introduce regressions, and will change behaviour for existing users, possibly preventing them from using their existing configuration. For this reason, we will not be fixing this issue in stable releases.
Patch details
Package | Patch details |
---|---|
sudo |
|