Jump to content

Advisories MDVSA-2010:118: sudo


paul
 Share

Recommended Posts

A vulnerability has been discovered and corrected in sudo:

 

The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and

1.7.0 through 1.7.2p6 does not properly handle an environment that

contains multiple PATH variables, which might allow local users

to gain privileges via a crafted value of the last PATH variable

(CVE-2010-1646).

 

Packages for 2008.0 and 2009.0 are provided as of the Extended

Maintenance Program. Please visit this link to learn more:

http://store.mandriva.com/product_info.php?cPath=149&products_id=490

 

The updated packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...