Open Vulnerability and Assessment Language (OVAL)
Contact Us Downloads News July 2, 2009 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:1242 Date: 2005-07-18
Title: sudo Symlink Vulnerability
Description: Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.
Version: 1 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2005-1993
Family: unix
Platform(s): Red Hat Enterprise Linux 3 Product(s): sudo
Definition Synopsis:

OVAL is CVE Compatible