Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200506-22 ] sudo: Arbitrary command execution
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Advocate
Advocate


Joined: 12 May 2004
Posts: 2663

PostPosted: Thu Jun 23, 2005 7:47 am    Post subject: [ GLSA 200506-22 ] sudo: Arbitrary command execution Reply with quote

Gentoo Linux Security Advisory

Title: sudo: Arbitrary command execution (GLSA 200506-22)
Severity: normal
Exploitable: local
Date: June 23, 2005
Bug(s): #96618
ID: 200506-22

Synopsis

A vulnerability in sudo may allow local users to elevate privileges.

Background

sudo allows a system administrator to give users the ability to run commands as other users.

Affected Packages

Package: app-admin/sudo
Vulnerable: < 1.6.8_p9
Unaffected: >= 1.6.8_p9
Architectures: All supported architectures


Description

The sudoers file is used to define the actions sudo users are permitted to perform. Charles Morris discovered that a specific layout of the sudoers file could cause the results of an internal check to be clobbered, leaving sudo vulnerable to a race condition.

Impact

Successful exploitation would permit a local sudo user to execute arbitrary commands as another user.

Workaround

Reorder the sudoers file using the visudo utility to ensure the 'ALL' pseudo-command precedes other command definitions.

Resolution

All sudo users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-admin/sudo-1.6.8_p9"


References

Sudo Announcement


Last edited by GLSA on Mon Dec 31, 2007 4:17 am; edited 3 times in total
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum