Open Vulnerability and Assessment Language (OVAL)
Offical Language Release Repository Downloads News — November 5, 2009 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:1242 Date: 2005-07-18
Title: sudo Symlink Vulnerability
Description: Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.
Version: 1 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2005-1993
Family: unix
Platform(s): Red Hat Enterprise Linux 3 Product(s): sudo
Definition Synopsis: