A flaw exists in sudo’s -e option (aka sudoedit) in sudo versions 1.6.9 through 1.7.2p3 that may give a user with permission to run sudoedit the ability to run arbitrary commands. Sudo versions affected: 1.6.9 through 1.7.2p3 inclusive. CVE ID: This vulnerability has been assigned CVE-2010-0426 in the Common Vulnerabilities and Exposures database.