LWN.net Logo

Fedora alert FEDORA-2011-0470 (sudo)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 14 Update: sudo-1.7.4p5-1.fc14
Date:  Tue, 18 Jan 2011 21:40:13 +0000
Message-ID:  <20110118214013.B5D4D10F950@bastion02.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2011-0470 2011-01-17 20:21:09 -------------------------------------------------------------------------------- Name : sudo Product : Fedora 14 Version : 1.7.4p5 Release : 1.fc14 URL : http://www.courtesan.com/sudo/ Summary : Allows restricted root access for specified users Description : Sudo (superuser do) allows a system administrator to give certain users (or groups of users) the ability to run some (or all) commands as root while logging all commands and arguments. Sudo operates on a per-command basis. It is not a replacement for the shell. Features include: the ability to restrict what commands a user may run on a per-host basis, copious logging of each command (providing a clear audit trail of who did what), a configurable timeout of the sudo command, and the ability to use the same configuration file (sudoers) on many different machines. -------------------------------------------------------------------------------- Update Information: - rebase to 1.7.4p5 - fixed sudo-1.7.4p4-getgrouplist.patch - fixes CVE-2011-0008, CVE-2011-0010 -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 17 2011 Daniel Kopecek <dkopecek@redhat.com> - 1.7.4p5-1 - rebase to 1.7.4p5 - fixed sudo-1.7.4p4-getgrouplist.patch - fixes CVE-2011-0008, CVE-2011-0010 * Tue Nov 30 2010 Daniel Kopecek <dkopecek@redhat.com> - 1.7.4p4-4 - sync configuration paths with the nss_ldap package (rhbz#652687) -------------------------------------------------------------------------------- References: [ 1 ] Bug #668879 - CVE-2011-0010 sudo: does not ask for password on GID changes https://bugzilla.redhat.com/show_bug.cgi?id=668879 [ 2 ] Bug #668843 - CVE-2011-0008 sudo in Fedora vulnerable to CVE-2009-0034 again due to improper patch rediff https://bugzilla.redhat.com/show_bug.cgi?id=668843 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update sudo' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds