Family: Fedora Local Security Checks --> Category: infos
Fedora Core 4 2005-473: sudo Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the sudo package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory FEDORA-2005-473 (sudo).
Sudo (superuser do) allows a system administrator to give certain
users (or groups of users) the ability to run some (or all) commands
as root while logging all commands and arguments. Sudo operates on a
per-command basis. It is not a replacement for the shell. Features
include: the ability to restrict what commands a user may run on a
per-host basis, copious logging of each command (providing a clear
audit trail of who did what), a configurable timeout of the sudo
command, and the ability to use the same configuration file (sudoers)
on many different machines.
* Tue Jun 21 2005 Karel Zak 1.6.8p8-2.2
- fix #161116 - CVE-2005-1993 sudo trusted user arbitrary command execution
Solution : http://fedoranews.org//mediawiki/index.php/Fedora_Core_4_Update:_sudo-1.6.8p8-2.2
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.