{ "schema_version": "1.4.0", "id": "GHSA-cxqf-2pgv-vx9p", "modified": "2025-04-12T12:54:07Z", "published": "2022-05-17T03:27:05Z", "aliases": [ "CVE-2015-5602" ], "details": "sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by \"/home/*/*/file.txt.\"", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-5602" }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/201606-13" }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/37710" }, { "type": "WEB", "url": "http://bugzilla.sudo.ws/show_bug.cgi?id=707" }, { "type": "WEB", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171024.html" }, { "type": "WEB", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171054.html" }, { "type": "WEB", "url": "http://www.debian.org/security/2016/dsa-3440" }, { "type": "WEB", "url": "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1034392" }, { "type": "WEB", "url": "http://www.sudo.ws/stable.html#1.8.15" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2015-11-17T15:59:00Z" } }