Vulnerability & Exploit Database

Back to search

RHSA-2013:1701: sudo security, bug fix and enhancement update

Severity CVSS Published Added Modified
7 (AV:L/AC:M/Au:N/C:C/I:C/A:C) March 04, 2013 November 20, 2013 July 03, 2017

Available Exploits 

Description

The sudo (superuser do) utility allows system administrators to givecertain users the ability to run commands as root.A flaw was found in the way sudo handled time stamp files. An attacker ableto run code as a local user and with the ability to control the systemclock could possibly gain additional privileges by running commands thatthe victim user was allowed to run via sudo, without knowing the victim'spassword. (CVE-2013-1775)It was found that sudo did not properly validate the controlling terminaldevice when the tty_tickets option was enabled in the /etc/sudoers file.An attacker able to run code as a local user could possibly gain additionalprivileges by running commands that the victim user was allowed to run viasudo, without knowing the victim's password. (CVE-2013-2776, CVE-2013-2777)This update also fixes the following bugs:In addition, this update adds the following enhancements:All sudo users are advised to upgrade to this updated package, whichcontains backported patches to correct these issues and addthese enhancements.

Free Nexpose Download

Discover, prioritize, and remediate security risks today!

 Download now

References

Solution

redhat-upgrade-sudo

Related Vulnerabilities