LWN.net Logo

sudo: privilege escalation

Package(s):sudo CVE #(s):CVE-2013-1776
Created:March 4, 2013 Updated:March 20, 2013
Description: From the Mageia advisory:

Sudo before 1.8.6p7 allows a malicious user to run commands via sudo without authenticating, so long as there exists a terminal the user has access to where a sudo command was successfully run by that same user within the password timeout period (usually five minutes).

Alerts:
Mageia MGASA-2013-0078 2013-03-01
Slackware SSA:2013-065-01 2013-03-06
Debian DSA-2642-1 2013-03-09
Mandriva MDVSA-2013:026 2013-03-18
Fedora FEDORA-2013-3297 2013-03-16
Fedora FEDORA-2013-3270 2013-03-19
openSUSE openSUSE-SU-2013:0495-1 2013-03-20
openSUSE openSUSE-SU-2013:0503-1 2013-03-20
Mandriva MDVSA-2013:054 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds