LWN.net Logo

sudo: group-related vulnerabilities

Package(s):sudo CVE #(s):CVE-2011-0008 CVE-2011-0010
Created:January 19, 2011 Updated:March 22, 2012
Description: It turns out that sudo does not ask for a password on group ID changes. CVE-2011-0008 is the return of CVE-2009-0034 (another group-oriented vulnerability) as the result of upstream changes.
Alerts:
Pardus 2011-31 2011-02-12
Slackware SSA:2011-041-05 2011-02-11
Red Hat RHSA-2011:0599-01 2011-05-19
Mandriva MDVSA-2011:018 2011-01-21
Ubuntu USN-1046-1 2011-01-20
openSUSE openSUSE-SU-2011:0050-1 2011-01-19
SUSE SUSE-SR:2011:002 2011-01-25
Fedora FEDORA-2011-0455 2011-01-17
Fedora FEDORA-2011-0470 2011-01-17
Red Hat RHSA-2012:0309-03 2012-02-21
Gentoo 201203-06 2012-03-05
Oracle ELSA-2012-0309 2012-03-07
Scientific Linux SL-sudo-20120321 2012-03-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds