mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-12-13 23:37:08 +00:00
153 lines
4.5 KiB
JSON
153 lines
4.5 KiB
JSON
{
|
|
"CVE_data_meta" : {
|
|
"ASSIGNER" : "cve@mitre.org",
|
|
"ID" : "CVE-2005-4158",
|
|
"STATE" : "PUBLIC"
|
|
},
|
|
"affects" : {
|
|
"vendor" : {
|
|
"vendor_data" : [
|
|
{
|
|
"product" : {
|
|
"product_data" : [
|
|
{
|
|
"product_name" : "n/a",
|
|
"version" : {
|
|
"version_data" : [
|
|
{
|
|
"version_value" : "n/a"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"vendor_name" : "n/a"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"data_format" : "MITRE",
|
|
"data_type" : "CVE",
|
|
"data_version" : "4.0",
|
|
"description" : {
|
|
"description_data" : [
|
|
{
|
|
"lang" : "eng",
|
|
"value" : "Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script."
|
|
}
|
|
]
|
|
},
|
|
"problemtype" : {
|
|
"problemtype_data" : [
|
|
{
|
|
"description" : [
|
|
{
|
|
"lang" : "eng",
|
|
"value" : "n/a"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"references" : {
|
|
"reference_data" : [
|
|
{
|
|
"name" : "http://www.sudo.ws/sudo/alerts/perl_env.html",
|
|
"refsource" : "CONFIRM",
|
|
"url" : "http://www.sudo.ws/sudo/alerts/perl_env.html"
|
|
},
|
|
{
|
|
"name" : "DSA-946",
|
|
"refsource" : "DEBIAN",
|
|
"url" : "http://www.debian.org/security/2006/dsa-946"
|
|
},
|
|
{
|
|
"name" : "MDKSA-2005:234",
|
|
"refsource" : "MANDRAKE",
|
|
"url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2005:234"
|
|
},
|
|
{
|
|
"name" : "MDKSA-2006:159",
|
|
"refsource" : "MANDRIVA",
|
|
"url" : "http://www.mandriva.com/security/advisories?name=MDKSA-2006:159"
|
|
},
|
|
{
|
|
"name" : "SUSE-SR:2006:002",
|
|
"refsource" : "SUSE",
|
|
"url" : "http://www.novell.com/linux/security/advisories/2006_02_sr.html"
|
|
},
|
|
{
|
|
"name" : "2006-0002",
|
|
"refsource" : "TRUSTIX",
|
|
"url" : "http://www.trustix.org/errata/2006/0002/"
|
|
},
|
|
{
|
|
"name" : "USN-235-1",
|
|
"refsource" : "UBUNTU",
|
|
"url" : "https://www.ubuntu.com/usn/usn-235-1/"
|
|
},
|
|
{
|
|
"name" : "15394",
|
|
"refsource" : "BID",
|
|
"url" : "http://www.securityfocus.com/bid/15394"
|
|
},
|
|
{
|
|
"name" : "ADV-2005-2386",
|
|
"refsource" : "VUPEN",
|
|
"url" : "http://www.vupen.com/english/advisories/2005/2386"
|
|
},
|
|
{
|
|
"name" : "1015192",
|
|
"refsource" : "SECTRACK",
|
|
"url" : "http://securitytracker.com/alerts/2005/Nov/1015192.html"
|
|
},
|
|
{
|
|
"name" : "17534",
|
|
"refsource" : "SECUNIA",
|
|
"url" : "http://secunia.com/advisories/17534/"
|
|
},
|
|
{
|
|
"name" : "18156",
|
|
"refsource" : "SECUNIA",
|
|
"url" : "http://secunia.com/advisories/18156"
|
|
},
|
|
{
|
|
"name" : "18308",
|
|
"refsource" : "SECUNIA",
|
|
"url" : "http://secunia.com/advisories/18308"
|
|
},
|
|
{
|
|
"name" : "18549",
|
|
"refsource" : "SECUNIA",
|
|
"url" : "http://secunia.com/advisories/18549"
|
|
},
|
|
{
|
|
"name" : "18102",
|
|
"refsource" : "SECUNIA",
|
|
"url" : "http://secunia.com/advisories/18102"
|
|
},
|
|
{
|
|
"name" : "18558",
|
|
"refsource" : "SECUNIA",
|
|
"url" : "http://secunia.com/advisories/18558"
|
|
},
|
|
{
|
|
"name" : "18463",
|
|
"refsource" : "SECUNIA",
|
|
"url" : "http://secunia.com/advisories/18463"
|
|
},
|
|
{
|
|
"name" : "21692",
|
|
"refsource" : "SECUNIA",
|
|
"url" : "http://secunia.com/advisories/21692"
|
|
},
|
|
{
|
|
"name" : "sudo-perl-execute-code(23102)",
|
|
"refsource" : "XF",
|
|
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/23102"
|
|
}
|
|
]
|
|
}
|
|
}
|