Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/14665 | mailing list exploit vendor advisory |
http://www.securityfocus.com/bid/321 | vdb entry vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/2277 | vdb entry |