Summary: | app-admin/sudo 1.6.8p9 fixes race condition | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Rajiv Aaron Manglani (RETIRED) <rajiv> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | kfm |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Other | ||
URL: | http://www.sudo.ws/sudo/alerts/path_race.html | ||
Whiteboard: | B1 [glsa] jaervosz | ||
Package list: | Runtime testing required: | --- |
Description
Rajiv Aaron Manglani (RETIRED)
![]() sudo-1.6.8_p9 is in portage, but currently marked unstable on most arch's. ====================================================== Candidate: CAN-2005-1993 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1993 Reference: BUGTRAQ:20050620 Sudo version 1.6.8p9 now available, fixes security issue. Reference: URL:http://www.securityfocus.com/archive/1/402741 Reference: CONFIRM:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161116 Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack. Arches please test and mark sudo-1.6.8_p9. Stable on ppc. stable on ppc64 Stable on hppa amd64 stable Stable on sparc. IA64 done and happy. alpha done for you :) Cheers, Ferdy x86 please mark stable. stable on x86.. GLSA 200506-22 arm, mips, s390 please remember to mark stable to benifit from the GLSA. Stable on mips. |