VDB
DEBIAN-CVE-2014-0106
DEBIAN-CVE-2014-0106
PUBLISHED
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | sudo | 0, 0, 0 |
| Debian:14 | sudo | 0, 0, 0 |
| Debian:11 | sudo | 0, 0, 0 |
| Debian:12 | sudo | 0, 0, 0 |
Timeline
- Mar 11, 2014 CVE Published
- Apr 28, 2026 CVE Updated