CVE-1999-0958

CVSS 2.0 Score 7.2 of 10 (high)

Details

Published Jan 12, 1998
Updated: Nov 20, 2024

Summary

CVE-1999-0958 is a vulnerability affecting sudo version 1.5.x. This issue allows local users to execute arbitrary commands by exploiting a ".." (dot dot) attack. The vulnerability arises due to a lack of proper validation of user input, enabling attackers to manipulate the current working directory during the sudo command execution. This weakness poses a significant security risk, as it grants unauthorized access to system resources and functions. To mitigate this risk, it is essential to update sudo to a newer, more secure version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Todd Miller Sudo

Affected Vendors

  • Todd Miller