DEBIAN-CVE-2014-0106

Source
https://security-tracker.debian.org/tracker/CVE-2014-0106
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2014-0106.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2014-0106
Upstream
Published
2014-03-11T19:37:03Z
Modified
2025-09-19T06:08:24Z
Summary
[none]
Details

Sudo 1.6.9 before 1.8.5, when envreset is disabled, does not properly check environment variables for the envdelete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

References

Affected packages

Debian:11 / sudo

Package

Name
sudo
Purl
pkg:deb/debian/sudo?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.5p2-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / sudo

Package

Name
sudo
Purl
pkg:deb/debian/sudo?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.5p2-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / sudo

Package

Name
sudo
Purl
pkg:deb/debian/sudo?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.5p2-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:14 / sudo

Package

Name
sudo
Purl
pkg:deb/debian/sudo?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.5p2-1

Ecosystem specific

{
    "urgency": "low"
}