---
cve: "CVE-2015-5602"
severity: "LOW"
cvss: 3.1
epss: "1.5%"
vendor: "n/a"
kev: false
exploited: false
published: "2015-11-17 15:59:10"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-10T09:26:31+02:00"
---

# CVE-2015-5602

> 3.1 LOW · 🧪 PoC

## Beschreibung

sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt."

## Exploit-Evidenz

- [EDB-37710 — Sudo 1.8.14 (RHEL 5/6/7 / Ubuntu) - 'Sudoedit' Unauthorized Privilege Escalation](https://www.exploit-db.com/exploits/37710) ✅

## Referenzen

- <http://bugzilla.sudo.ws/show_bug.cgi?id=707>
- <http://www.sudo.ws/stable.html#1.8.15>
- <http://www.securitytracker.com/id/1034392>
- <http://www.debian.org/security/2016/dsa-3440>
- <https://security.gentoo.org/glsa/201606-13>
- <http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html>
- <http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171024.html>
- <https://www.exploit-db.com/exploits/37710/>
- <http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171054.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2015-5602) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
