sudo: privilege escalation
| Package(s): | sudo |
CVE #(s): | CVE-2016-7076
|
| Created: | November 14, 2016 |
Updated: | November 25, 2016 |
| Description: |
From the Red Hat advisory:
It was discovered that the sudo noexec restriction could have been bypassed if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges. |
| Alerts: |
|