CVE-2002-0043
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 0.9%
from disclosure to weapon0 days
Published on NVDJun 25
1st PoCJan 14
exploitation probability
0.9%top 42% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain root privileges by modifying environment variables and changing how the mail program is invoked.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/21227⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02%3A06.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000451http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:003http://marc.info/?l=bugtraq&m=101120193627756&w=2https://exchange.xforce.ibmcloud.com/vulnerabilities/7891http://www.debian.org/security/2002/dsa-101http://www.novell.com/linux/security/advisories/2002_002_sudo_txt.htmlhttp://www.redhat.com/support/errata/RHSA-2002-011.htmlhttp://www.redhat.com/support/errata/RHSA-2002-013.htmlhttp://www.securityfocus.com/advisories/3800http://www.securityfocus.com/archive/1/250168http://www.securityfocus.com/bid/3871