|
|
Log in / Subscribe / Register

sudo: privilege escalation

Package(s):sudo CVE #(s):CVE-2016-7032
Created:November 15, 2016 Updated:November 16, 2016
Description: From the Debian LTS advisory:

It was discovered that the sudo noexec restriction could have been bypassed if application run via sudo executed system(), popen() or wordexp() C library functions with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.

noexec bypass via system() and popen()

Alerts:
Debian-LTS DLA-707-1 sudo 2016-11-14
Scientific Linux SLSA-2016:2872-1 sudo 2016-12-14
Oracle ELSA-2016-2872 sudo 2016-12-06
Oracle ELSA-2016-2872 sudo 2016-12-06
CentOS CESA-2016:2872 sudo 2016-12-07
Red Hat RHSA-2016:2872-01 sudo 2016-12-06
openSUSE openSUSE-SU-2016:3004-1 sudo 2016-12-05
openSUSE openSUSE-SU-2016:2983-1 sudo 2016-12-02
openSUSE openSUSE-SU-2016:2878-1 sudo 2016-11-22

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds