|
|
Log in / Subscribe / Register

sudo: information disclosure

Package(s):sudo CVE #(s):CVE-2014-9680
Created:February 17, 2015 Updated:November 4, 2015
Description: From the sudo advisory:

Prior to sudo 1.8.12, the TZ environment variable was passed through unchecked. Most libc tzset() implementations support passing an absolute pathname in the time zone to point to an arbitrary, user-controlled file. This may be used to exploit bugs in the C library's TZ parser or open files the user would not otherwise have access to. Arbitrary file access via TZ could also be used in a denial of service attack by reading from a file or fifo that will block.

Alerts:
openSUSE openSUSE-SU-2016:3004-1 sudo 2016-12-05
openSUSE openSUSE-SU-2016:2983-1 sudo 2016-12-02
openSUSE openSUSE-SU-2015:1913-1 sudo 2015-11-04
openSUSE openSUSE-SU-2015:1849-1 sudo 2015-10-30
Scientific Linux SLSA-2015:1409-1 sudo 2015-08-03
Oracle ELSA-2015-1409 sudo 2015-07-29
Red Hat RHSA-2015:1409-01 sudo 2015-07-22
Gentoo 201504-02 sudo 2015-04-11
Mandriva MDVSA-2015:126 sudo 2015-03-29
Ubuntu USN-2533-1 sudo 2015-03-16
Fedora FEDORA-2015-2247 sudo 2015-02-23
Fedora FEDORA-2015-2281 sudo 2015-02-22
Debian DSA-3167-1 sudo 2015-02-22
Mageia MGASA-2015-0079 sudo 2015-02-19
Slackware SSA:2015-047-03 sudo 2015-02-16
Debian-LTS DLA-160-1 sudo 2015-02-27

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds