LWN.net Logo

sudo: privilege escalation

Package(s):sudo CVE #(s):CVE-2013-1775
Created:February 28, 2013 Updated:March 20, 2013
Description:

From the Ubuntu advisory:

Marco Schoepl discovered that Sudo incorrectly handled time stamp files when the system clock is set to epoch. A local attacker could use this issue to run Sudo commands without a password prompt.

Alerts:
Ubuntu USN-1754-1 2013-02-28
Mageia MGASA-2013-0078 2013-03-01
Slackware SSA:2013-065-01 2013-03-06
Debian DSA-2642-1 2013-03-09
Mandriva MDVSA-2013:026 2013-03-18
Fedora FEDORA-2013-3297 2013-03-16
Fedora FEDORA-2013-3270 2013-03-19
openSUSE openSUSE-SU-2013:0495-1 2013-03-20
openSUSE openSUSE-SU-2013:0503-1 2013-03-20
Mandriva MDVSA-2013:054 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds