REDHAT-BUG-668843: Medium severity centos sudo vulnerability
Due to upstream changes in how sudo 1.7.3 handles group membership checks, the patch used to correct bug #235915 (sudo can't always correctly determine group memberships) was incorrectly rediffed, making sudo in Fedora once again vulnerable to CVE-2009-0034 (incorrect handling of groups in RunasUser).
Statement:
Not vulnerable. This issue did not affect the versions of sudo as shipped with Red Hat Enterprise Linux 4, 5, or 6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-668843?
The severity of REDHAT-BUG-668843 is classified as important due to its potential impact on group membership checks.
How do I fix REDHAT-BUG-668843?
To fix REDHAT-BUG-668843, you should update your sudo package to the latest version that addresses this issue.
What versions of sudo are affected by REDHAT-BUG-668843?
REDHAT-BUG-668843 affects sudo versions prior to 1.7.3.
What are the implications of not fixing REDHAT-BUG-668843?
Not fixing REDHAT-BUG-668843 may lead to unauthorized access due to incorrect group membership determination.
Where can I find more details on REDHAT-BUG-668843?
More details on REDHAT-BUG-668843 can be found in the Red Hat bug tracking system.