Skip to content

CVE-2014-0106

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0005 (0.1%)
Percentile: 15.9%
EPSS: 2026-05-06

Affects

apple:mac_os_xtodd_miller:sudo

Technical description

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

Published: 3/11/2014, 7:37:03 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam