Anfälligkeitssuche        Suche in 172616 CVE Beschreibungen
und 81291 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.840571
Kategorie:Ubuntu Local Security Checks
Titel:Ubuntu Update for sudo vulnerability USN-1046-1
Zusammenfassung:Ubuntu Update for Linux kernel vulnerabilities USN-1046-1
Beschreibung:Summary:
Ubuntu Update for Linux kernel vulnerabilities USN-1046-1

Vulnerability Insight:
Alexander Kurtz discovered that sudo would not prompt for a password when
a group was specified in the Runas_Spec. A local attacker could exploit
this to execute arbitrary code as the specified group if sudo was
configured to allow the attacker to use a program as this group. The group
Runas_Spec is not used in the default installation of Ubuntu.

Affected Software/OS:
sudo vulnerability on Ubuntu 9.10,
Ubuntu 10.04 LTS,
Ubuntu 10.10

Solution:
Please Install the Updated Packages.

CVSS Score:
4.4

CVSS Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-0010
BugTraq ID: 45774
http://www.securityfocus.com/bid/45774
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053341.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053263.html
http://security.gentoo.org/glsa/glsa-201203-06.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2011:018
http://www.sudo.ws/repos/sudo/rev/07d1b0ce530e
http://openwall.com/lists/oss-security/2011/01/11/3
http://openwall.com/lists/oss-security/2011/01/12/1
http://openwall.com/lists/oss-security/2011/01/12/3
http://www.osvdb.org/70400
http://www.redhat.com/support/errata/RHSA-2011-0599.html
http://secunia.com/advisories/42886
http://secunia.com/advisories/42949
http://secunia.com/advisories/42968
http://secunia.com/advisories/43068
http://secunia.com/advisories/43282
http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.593654
SuSE Security Announcement: SUSE-SR:2011:002 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
http://www.ubuntu.com/usn/USN-1046-1
http://www.vupen.com/english/advisories/2011/0089
http://www.vupen.com/english/advisories/2011/0182
http://www.vupen.com/english/advisories/2011/0195
http://www.vupen.com/english/advisories/2011/0199
http://www.vupen.com/english/advisories/2011/0212
http://www.vupen.com/english/advisories/2011/0362
XForce ISS Database: sudo-groupid-privilege-escalation(64636)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64636
CopyrightCopyright (c) 2011 Greenbone Networks GmbH

Dies ist nur einer von 81291 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2020 E-Soft Inc. Alle Rechte vorbehalten.