Family: Ubuntu Local Security Checks --> Category: infos
USN213-1 : sudo vulnerability Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
The remote package "sudo" is missing a security patch.
Tavis Ormandy discovered a privilege escalation vulnerability in sudo.
On executing shell scripts with sudo, the "P4" and "SHELLOPTS"
environment variables were not cleaned properly. If sudo is set up to
grant limited sudo rights to normal users this could be exploited
to run arbitrary commands as the target user.
Updated packags for Ubuntu 4.10:
Upgrade to :
- sudo-1.6.8p9-2ubuntu2.1 (Ubuntu 4.10)
- sudo-1.6.8p9-2ubuntu2.1 (Ubuntu 5.04)
- sudo-1.6.8p9-2ubuntu2.1 (Ubuntu 5.10)
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.