A race condition exists in Sudo’s command pathname handling prior to Sudo version 1.6.8p9 that could allow a user with Sudo privileges to run arbitrary commands.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/38192/sudo168-9.txt
Source: https://packetstormsecurity.com/files/38192/sudo168-9.txt.html

