First published: Thu May 10 2012(Updated: )
A security flaw was found in the way sudo granted access for particular host, when multiple netmask values have been used in sudo's Host / Host_List configuration. Such configuration allowed unprivileged users, who were authorized by the sudoers file to run their sudo commands, to run these commands from any host regardless of the Host_List configuration (even from hosts, which were intended according to the Host_List netmask configuration not to allow execution of such commands according to the netmask).
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Todd Miller Sudo | =1.6 | |
Todd Miller Sudo | =1.6.1 | |
Todd Miller Sudo | =1.6.2 | |
Todd Miller Sudo | =1.6.2p3 | |
Todd Miller Sudo | =1.6.3 | |
Todd Miller Sudo | =1.6.3_p7 | |
Todd Miller Sudo | =1.6.4 | |
Todd Miller Sudo | =1.6.4p2 | |
Todd Miller Sudo | =1.6.5 | |
Todd Miller Sudo | =1.6.6 | |
Todd Miller Sudo | =1.6.7 | |
Todd Miller Sudo | =1.6.7p5 | |
Todd Miller Sudo | =1.6.8 | |
Todd Miller Sudo | =1.6.8p12 | |
Todd Miller Sudo | =1.6.9 | |
Todd Miller Sudo | =1.6.9p20 | |
Todd Miller Sudo | =1.6.9p21 | |
Todd Miller Sudo | =1.6.9p22 | |
Todd Miller Sudo | =1.6.9p23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.