The sudo (superuser do) utility allows system administrators to givecertain users the ability to run commands as root.A flaw was found in the sudo password checking logic. In configurationswhere the sudoers settings allowed a user to run a command using sudo withonly the group ID changed, sudo failed to prompt for the user's passwordbefore running the specified command with the elevated group privileges.(CVE-2011-0010)This update also fixes the following bugs:All users of sudo are advised to upgrade to this updated package, whichresolves these issues.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center