| From: |
| Eren Turkay <eren@pardus.org.tr> |
| To: |
| pardus-security@pardus.org.tr |
| Subject: |
| [Pardus-security] [PLSA 2010-80] Sudo: Privilege Escalation |
| Date: |
| Tue, 15 Jun 2010 12:39:35 +0300 (EEST) |
| Message-ID: |
| <20100615093935.DE9ABA7AC79@lider.pardus.org.tr> |
| Archive-link: |
| Article, Thread
|
------------------------------------------------------------------------
Pardus Linux Security Advisory 2010-80 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2010-06-15
Severity: 3
Type: Local
------------------------------------------------------------------------
Summary
=======
A vulnerability has been fixed in sudo which can be exploited to allow
local users to gain privileges.
Description
===========
CVE-2010-1646:
The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and
1.7.0 through 1.7.2p6 does not properly handle an environment that
contains multiple PATH variables, which might allow local users to gain
privileges via a crafted value of the last PATH variable.
Affected packages:
Pardus 2009:
sudo, all before 1.7.2_p7-27-8
Resolution
==========
There are update(s) for sudo. You can update them via Package Manager or
with a single command from console:
pisi up sudo
References
==========
* http://bugs.pardus.org.tr/show_bug.cgi?id=13369
------------------------------------------------------------------------
_______________________________________________
Pardus-security mailing list
Pardus-security@pardus.org.tr
http://liste.pardus.org.tr/mailman/listinfo/pardus-security
(
Log in to post comments)