LWN.net Logo

sudo: privilege escalation

Package(s):sudo CVE #(s):CVE-2010-1646
Created:June 15, 2010 Updated:January 25, 2011
Description: From the Pardus advisory:

The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.

Alerts:
SUSE SUSE-SR:2011:002 2011-01-25
openSUSE openSUSE-SU-2011:0050-1 2011-01-19
rPath rPSA-2010-0075-1 2010-10-27
Gentoo 201009-03 2010-09-07
Fedora FEDORA-2010-9415 2010-06-02
CentOS CESA-2010:0475 2010-06-16
Red Hat RHSA-2010:0475-01 2010-06-15
Mandriva MDVSA-2010:118 2010-06-17
Debian DSA-2062-1 2010-06-17
Fedora FEDORA-2010-9402 2010-06-02
Pardus 2010-80 2010-06-15
MeeGo MeeGo-SA-10:06 2010-07-07
Ubuntu USN-956-1 2010-06-30
Fedora FEDORA-2010-9417 2010-06-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds