Computer Security
[EN] securityvulns.ru
no-pyccku



sudo protection bypass
updated since 01.03.2010
Published:22.04.2010
Source:BUGTRAQ
SecurityVulns ID:10655
Type:local
Level:6/10
Description:when a pseudocommand is enabled, it's possible to created an executable file with the same name, it will be executed by relative name with escalated privileges.
CVE:CVE-2010-1163
 CVE-2010-0426
Original documentdocumentAgazzini Maurizio, sudoedit local privilege escalation through PATH manipulation (22.04.2010)
 documentUBUNTU, [USN-928-1] Sudo vulnerability (19.04.2010)
 documentKingcope Kingcope, Todd Miller Sudo local root exploit discovered by Slouching (02.03.2010)
 documentMANDRIVA, [ MDVSA-2010:049 ] sudo (01.03.2010)
Files:Tod Miller Sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4
Discuss:Read or add your comments to this news (2 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 



Rating@Mail.ru