CVE-2015-5602: Sudo Project Sudo

High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.

sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt."

Affected products

Published 2015-11-17. Last modified 2026-06-17.