CVE-2014-0106

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.

Published: 2014-03-11 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2014-0106 is rated Low Risk (35.6/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.34%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2014-0106

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.05% 0.34% +0.29%
2 2025-06-03 0.04% 0.05% +0.01%
3 2025-05-30 0.04%

Full EPSS history (8 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2014-0106

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.6 2.0 MEDIUM
AV:L/AC:M/Au:S/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:S)
A single authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
2.7 10.0 [email protected]

Weakness enumeration for CVE-2014-0106

OS Trackers for CVE-2014-0106

vendor priority summary link
debian low CVE-2014-0106 low priority: Debian including 1 source packages (sudo), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2014-0106
gentoo high CVE-2014-0106: 1 GLSA(s) (201406-30), 1 atom(s) (app-admin/sudo); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2014-0106
redhat medium https://access.redhat.com/security/cve/CVE-2014-0106
ubuntu medium CVE-2014-0106 medium priority: Ubuntu including 1 source packages (sudo), 5 status rows across 5 suites (lucid, precise, quantal, saucy, upstream): released 3, not-affected 2. https://ubuntu.com/security/CVE-2014-0106

Affected software / configurations for CVE-2014-0106

Vendor Product Version Raw CPE
apple mac_os_x <= 10.10.4 cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
todd_miller sudo 1.6.9 cpe:2.3:a:todd_miller:sudo:1.6.9:*:*:*:*:*:*:*
todd_miller sudo 1.6.9p20 cpe:2.3:a:todd_miller:sudo:1.6.9p20:*:*:*:*:*:*:*
todd_miller sudo 1.6.9p21 cpe:2.3:a:todd_miller:sudo:1.6.9p21:*:*:*:*:*:*:*
todd_miller sudo 1.6.9p22 cpe:2.3:a:todd_miller:sudo:1.6.9p22:*:*:*:*:*:*:*
todd_miller sudo 1.6.9p23 cpe:2.3:a:todd_miller:sudo:1.6.9p23:*:*:*:*:*:*:*
todd_miller sudo 1.7.0 cpe:2.3:a:todd_miller:sudo:1.7.0:*:*:*:*:*:*:*
todd_miller sudo 1.7.1 cpe:2.3:a:todd_miller:sudo:1.7.1:*:*:*:*:*:*:*
todd_miller sudo 1.7.2 cpe:2.3:a:todd_miller:sudo:1.7.2:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p1 cpe:2.3:a:todd_miller:sudo:1.7.2p1:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p2 cpe:2.3:a:todd_miller:sudo:1.7.2p2:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p3 cpe:2.3:a:todd_miller:sudo:1.7.2p3:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p4 cpe:2.3:a:todd_miller:sudo:1.7.2p4:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p5 cpe:2.3:a:todd_miller:sudo:1.7.2p5:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p6 cpe:2.3:a:todd_miller:sudo:1.7.2p6:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p7 cpe:2.3:a:todd_miller:sudo:1.7.2p7:*:*:*:*:*:*:*
todd_miller sudo 1.7.3b1 cpe:2.3:a:todd_miller:sudo:1.7.3b1:*:*:*:*:*:*:*
todd_miller sudo 1.7.4 cpe:2.3:a:todd_miller:sudo:1.7.4:*:*:*:*:*:*:*
todd_miller sudo 1.7.4p1 cpe:2.3:a:todd_miller:sudo:1.7.4p1:*:*:*:*:*:*:*
todd_miller sudo 1.7.4p2 cpe:2.3:a:todd_miller:sudo:1.7.4p2:*:*:*:*:*:*:*
todd_miller sudo 1.7.4p3 cpe:2.3:a:todd_miller:sudo:1.7.4p3:*:*:*:*:*:*:*
todd_miller sudo 1.7.4p4 cpe:2.3:a:todd_miller:sudo:1.7.4p4:*:*:*:*:*:*:*
todd_miller sudo 1.7.4p5 cpe:2.3:a:todd_miller:sudo:1.7.4p5:*:*:*:*:*:*:*
todd_miller sudo 1.7.4p6 cpe:2.3:a:todd_miller:sudo:1.7.4p6:*:*:*:*:*:*:*
todd_miller sudo 1.7.5 cpe:2.3:a:todd_miller:sudo:1.7.5:*:*:*:*:*:*:*
todd_miller sudo 1.7.6 cpe:2.3:a:todd_miller:sudo:1.7.6:*:*:*:*:*:*:*
todd_miller sudo 1.7.6p1 cpe:2.3:a:todd_miller:sudo:1.7.6p1:*:*:*:*:*:*:*
todd_miller sudo 1.7.6p2 cpe:2.3:a:todd_miller:sudo:1.7.6p2:*:*:*:*:*:*:*
todd_miller sudo 1.7.7 cpe:2.3:a:todd_miller:sudo:1.7.7:*:*:*:*:*:*:*
todd_miller sudo 1.7.8 cpe:2.3:a:todd_miller:sudo:1.7.8:*:*:*:*:*:*:*
todd_miller sudo 1.7.8p1 cpe:2.3:a:todd_miller:sudo:1.7.8p1:*:*:*:*:*:*:*
todd_miller sudo 1.7.8p2 cpe:2.3:a:todd_miller:sudo:1.7.8p2:*:*:*:*:*:*:*
todd_miller sudo 1.7.9 cpe:2.3:a:todd_miller:sudo:1.7.9:*:*:*:*:*:*:*
todd_miller sudo 1.7.9p1 cpe:2.3:a:todd_miller:sudo:1.7.9p1:*:*:*:*:*:*:*
todd_miller sudo 1.7.10 cpe:2.3:a:todd_miller:sudo:1.7.10:*:*:*:*:*:*:*
todd_miller sudo 1.7.10p1 cpe:2.3:a:todd_miller:sudo:1.7.10p1:*:*:*:*:*:*:*
todd_miller sudo 1.7.10p2 cpe:2.3:a:todd_miller:sudo:1.7.10p2:*:*:*:*:*:*:*
todd_miller sudo 1.7.10p3 cpe:2.3:a:todd_miller:sudo:1.7.10p3:*:*:*:*:*:*:*
todd_miller sudo 1.7.10p4 cpe:2.3:a:todd_miller:sudo:1.7.10p4:*:*:*:*:*:*:*
todd_miller sudo 1.7.10p5 cpe:2.3:a:todd_miller:sudo:1.7.10p5:*:*:*:*:*:*:*
todd_miller sudo 1.7.10p6 cpe:2.3:a:todd_miller:sudo:1.7.10p6:*:*:*:*:*:*:*
todd_miller sudo 1.7.10p7 cpe:2.3:a:todd_miller:sudo:1.7.10p7:*:*:*:*:*:*:*
todd_miller sudo 1.7.10p8 cpe:2.3:a:todd_miller:sudo:1.7.10p8:*:*:*:*:*:*:*
todd_miller sudo 1.7.10p9 cpe:2.3:a:todd_miller:sudo:1.7.10p9:*:*:*:*:*:*:*
todd_miller sudo 1.7.10p10 cpe:2.3:a:todd_miller:sudo:1.7.10p10:*:*:*:*:*:*:*
todd_miller sudo 1.8.0 cpe:2.3:a:todd_miller:sudo:1.8.0:*:*:*:*:*:*:*
todd_miller sudo 1.8.1 cpe:2.3:a:todd_miller:sudo:1.8.1:*:*:*:*:*:*:*
todd_miller sudo 1.8.1p1 cpe:2.3:a:todd_miller:sudo:1.8.1p1:*:*:*:*:*:*:*
todd_miller sudo 1.8.1p2 cpe:2.3:a:todd_miller:sudo:1.8.1p2:*:*:*:*:*:*:*
todd_miller sudo 1.8.2 cpe:2.3:a:todd_miller:sudo:1.8.2:*:*:*:*:*:*:*
todd_miller sudo 1.8.3 cpe:2.3:a:todd_miller:sudo:1.8.3:*:*:*:*:*:*:*
todd_miller sudo 1.8.3p1 cpe:2.3:a:todd_miller:sudo:1.8.3p1:*:*:*:*:*:*:*
todd_miller sudo 1.8.3p2 cpe:2.3:a:todd_miller:sudo:1.8.3p2:*:*:*:*:*:*:*
todd_miller sudo 1.8.4 cpe:2.3:a:todd_miller:sudo:1.8.4:*:*:*:*:*:*:*
todd_miller sudo 1.8.4p1 cpe:2.3:a:todd_miller:sudo:1.8.4p1:*:*:*:*:*:*:*
todd_miller sudo 1.8.4p2 cpe:2.3:a:todd_miller:sudo:1.8.4p2:*:*:*:*:*:*:*
todd_miller sudo 1.8.4p3 cpe:2.3:a:todd_miller:sudo:1.8.4p3:*:*:*:*:*:*:*
todd_miller sudo 1.8.4p4 cpe:2.3:a:todd_miller:sudo:1.8.4p4:*:*:*:*:*:*:*
todd_miller sudo 1.8.4p5 cpe:2.3:a:todd_miller:sudo:1.8.4p5:*:*:*:*:*:*:*

References for CVE-2014-0106

cvelogic Threat Intelligence