|
|
| |
|
| |
sudo: privilege escalation
| Package(s): | sudo |
CVE #(s): | CVE-2012-2337
|
| Created: | May 17, 2012 |
Updated: | July 17, 2012 |
| Description: |
From the Ubuntu advisory:
It was discovered that sudo incorrectly handled network masks when using Host
and Host_List. A local user who is listed in sudoers may be allowed to run
commands on unintended hosts when IPv4 network masks are used to grant access.
A local attacker could exploit this to bypass intended access restrictions. Host
and Host_List are not used in the default installation of Ubuntu. |
| Alerts: |
|
( Log in to post comments)
|
|
|