LWN.net Logo

Pardus alert 2010-80 (sudo)

From:  Eren Turkay <eren@pardus.org.tr>
To:  pardus-security@pardus.org.tr
Subject:  [Pardus-security] [PLSA 2010-80] Sudo: Privilege Escalation
Date:  Tue, 15 Jun 2010 12:39:35 +0300 (EEST)
Message-ID:  <20100615093935.DE9ABA7AC79@lider.pardus.org.tr>
Archive-link:  Article, Thread

------------------------------------------------------------------------ Pardus Linux Security Advisory 2010-80 security@pardus.org.tr ------------------------------------------------------------------------ Date: 2010-06-15 Severity: 3 Type: Local ------------------------------------------------------------------------ Summary ======= A vulnerability has been fixed in sudo which can be exploited to allow local users to gain privileges. Description =========== CVE-2010-1646: The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable. Affected packages: Pardus 2009: sudo, all before 1.7.2_p7-27-8 Resolution ========== There are update(s) for sudo. You can update them via Package Manager or with a single command from console: pisi up sudo References ========== * http://bugs.pardus.org.tr/show_bug.cgi?id=13369 ------------------------------------------------------------------------ _______________________________________________ Pardus-security mailing list Pardus-security@pardus.org.tr http://liste.pardus.org.tr/mailman/listinfo/pardus-security


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds