|
|
Subscribe / Log in / New account

sudo: arbitrary command execution

Package(s):sudo CVE #(s):
Created:May 3, 2010 Updated:May 5, 2010
Description: From the Red Hat bugzilla:

It was discovered that the original upstream fix for the sudo's sudoedit privilege escalation flaw known as CVE-2010-0426 did not fully resolve the issue. In configurations where sudo's ignore_dot option was set to off (default is on), the user allowed to sudoedit some file with the privileges of some user could run arbitrary command with the privileges of that user.

Alerts:
Fedora FEDORA-2010-6749 sudo 2010-04-16
Fedora FEDORA-2010-6701 sudo 2010-04-16

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds