CVE-2010-1646

NameCVE-2010-1646
DescriptionThe secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2062-1
NVD severitymedium
Debian Bugs585394

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
sudo (PTS)stretch1.8.19p1-2.1+deb9u2fixed
stretch (security)1.8.19p1-2.1+deb9u3fixed
buster, buster (security)1.8.27-1+deb10u3fixed
bullseye, sid1.9.5p2-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sudosourcelenny1.6.9p17-3DSA-2062-1
sudosource(unstable)1.7.2p7-1585394

Search for package or bug name: Reporting problems