|
Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2002:003: sudo Vulnerability Scan
Vulnerability Scan Summary Check for the version of the sudo package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2002:003 (sudo).
The SuSE Security Team discovered a vulnerability in sudo that can be exploited
to obtain root privilege because sudo is installed setuid root. A possible hacker
could trick sudo to log failed sudo calls executing the sendmail (or equivalent
mailer) program with root rights and an environment that is not completely
clean. This problem has been fixed upstream by the author in sudo 1.6.4 and it
is highly recommended that all users upgrade regardless of what mailer you are
using.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2002:003
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|