LWN.net Logo

sudo: privilege escalation

Package(s):sudo CVE #(s):CVE-2012-2337
Created:May 17, 2012 Updated:July 17, 2012
Description:

From the Ubuntu advisory:

It was discovered that sudo incorrectly handled network masks when using Host and Host_List. A local user who is listed in sudoers may be allowed to run commands on unintended hosts when IPv4 network masks are used to grant access. A local attacker could exploit this to bypass intended access restrictions. Host and Host_List are not used in the default installation of Ubuntu.

Alerts:
Ubuntu USN-1442-1 2012-05-16
Mandriva MDVSA-2012:079 2012-05-21
Debian DSA-2478-1 2012-05-23
openSUSE openSUSE-SU-2012:0652-1 2012-05-29
Fedora FEDORA-2012-7998 2012-05-29
Gentoo 201207-01 2012-07-09
Fedora FEDORA-2012-8021 2012-07-12
Red Hat RHSA-2012:1081-01 2012-07-16
CentOS CESA-2012:1081 2012-07-16
CentOS CESA-2012:1081 2012-07-16
Scientific Linux SL-sudo-20120716 2012-07-16
Oracle ELSA-2012-1081 2012-07-17
Oracle ELSA-2012-1081 2012-07-17
Mandriva MDVSA-2013:054 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds