Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.53966
Categoría:Red Hat Local Security Checks
Título:RedHat Security Advisory RHSA-2005:535
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory RHSA-2005:535.

The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root with logging.

A race condition bug was found in the way sudo handles pathnames. It is
possible that a local user with limited sudo access could create
a race condition that would allow the execution of arbitrary commands as
the root user. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-2005-1993 to this issue.

Users of sudo should update to this updated package, which contains a
backported patch and is not vulnerable to this issue.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2005-535.html
http://www.securityfocus.com/archive/1/402741/30/0/threaded

Risk factor : Medium

CVSS Score:
3.7

Referencia Cruzada: BugTraq ID: 15647
BugTraq ID: 13993
Common Vulnerability Exposure (CVE) ID: CVE-2005-1993
13993
http://www.securityfocus.com/bid/13993
15647
http://www.securityfocus.com/bid/15647
15744
http://secunia.com/advisories/15744
17396
http://www.osvdb.org/17396
17813
http://secunia.com/advisories/17813
20050620 Sudo version 1.6.8p9 now available, fixes security issue.
http://www.securityfocus.com/archive/1/402741
ADV-2005-0821
http://www.vupen.com/english/advisories/2005/0821
ADV-2005-2659
http://www.vupen.com/english/advisories/2005/2659
APPLE-SA-2005-11-29
http://docs.info.apple.com/article.html?artnum=302847
DSA-735
http://www.debian.org/security/2005/dsa-735
FLSA:162750
http://www.securityfocus.com/archive/1/425974/100/0/threaded
RHSA-2005:535
http://www.redhat.com/support/errata/RHSA-2005-535.html
SUSE-SA:2005:036
http://www.novell.com/linux/security/advisories/2005_36_sudo.html
http://www.sudo.ws/sudo/alerts/path_race.html
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161116
oval:org.mitre.oval:def:11341
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11341
oval:org.mitre.oval:def:1242
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1242
sudo-pathname-race-condition(21080)
https://exchange.xforce.ibmcloud.com/vulnerabilities/21080
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.