CVE-2015-5602: Sudo Project Sudo
High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt."
Affected products
- Sudo Project Sudo: up to and including 1.8.14
Published 2015-11-17. Last modified 2026-06-17.