sudo: privilege escalation
| Package(s): | sudo | CVE #(s): | CVE-2016-7032 | ||||||||||||||||||||||||||||||||||||
| Created: | November 15, 2016 | Updated: | November 16, 2016 | ||||||||||||||||||||||||||||||||||||
| Description: | From the Debian LTS advisory:
It was discovered that the sudo noexec restriction could have been bypassed if application run via sudo executed system(), popen() or wordexp() C library functions with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges. noexec bypass via system() and popen() | ||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||
