CVE-2017-7642

The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the encoded ruby script or scrub the PATH variable.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hashicorp:vagrant_vmware_fusion:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-08-02 19:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-7642

Mitre link : CVE-2017-7642

CVE.ORG link : CVE-2017-7642


JSON object : View

Products Affected

hashicorp

  • vagrant_vmware_fusion
CWE
CWE-426

Untrusted Search Path