First published: Tue Feb 23 2010(Updated: )
Sudo failed to properly reset group permissions, when "runas_default" option was used. If a local, unprivileged user was authorized by sudoers file to perform their sudo commands under default user account, it could lead to privilege escalation. Upstream bug report: <a href="http://www.gratisoft.us/bugzilla/show_bug.cgi?id=349">http://www.gratisoft.us/bugzilla/show_bug.cgi?id=349</a> Upstream patch: <a href="http://www.gratisoft.us/bugzilla/attachment.cgi?id=255">http://www.gratisoft.us/bugzilla/attachment.cgi?id=255</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Todd Miller Sudo |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.