![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.63324 |
Category: | Fedora Local Security Checks |
Title: | Fedora Core 10 FEDORA-2009-1074 (sudo) |
Summary: | The remote host is missing an update to sudo;announced via advisory FEDORA-2009-1074.;Note: This VT has been deprecated and is therefore no longer functional. |
Description: | Summary: The remote host is missing an update to sudo announced via advisory FEDORA-2009-1074. Note: This VT has been deprecated and is therefore no longer functional. Vulnerability Insight: Sudo (superuser do) allows a system administrator to give certain users (or groups of users) the ability to run some (or all) commands as root while logging all commands and arguments. Sudo operates on a per-command basis. It is not a replacement for the shell. Features include: the ability to restrict what commands a user may run on a per-host basis, copious logging of each command (providing a clear audit trail of who did what), a configurable timeout of the sudo command, and the ability to use the same configuration file (sudoers) on many different machines. Update Information: Fix for incorrect handling of groups in Runas_User ChangeLog: * Thu Jan 29 2009 Daniel Kopecek 1.6.9p17-5 - Fix for incorrect handling of groups in Runas_User Solution: Apply the appropriate updates. This update can be installed with the yum update program. Use su -c 'yum update sudo' at the command line. CVSS Score: 6.9 CVSS Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-0034 1021688 http://www.securitytracker.com/id?1021688 20090129 rPSA-2009-0021-1 sudo http://www.securityfocus.com/archive/1/500546/100/0/threaded 20090711 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl http://www.securityfocus.com/archive/1/504849/100/0/threaded 33517 http://www.securityfocus.com/bid/33517 33753 http://secunia.com/advisories/33753 33840 http://secunia.com/advisories/33840 33885 http://secunia.com/advisories/33885 35766 http://secunia.com/advisories/35766 51736 http://osvdb.org/51736 ADV-2009-1865 http://www.vupen.com/english/advisories/2009/1865 MDVSA-2009:033 http://www.mandriva.com/security/advisories?name=MDVSA-2009:033 RHSA-2009:0267 http://www.redhat.com/support/errata/RHSA-2009-0267.html [Security-announce] 20090710 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl http://lists.vmware.com/pipermail/security-announce/2009/000060.html http://wiki.rpath.com/Advisories:rPSA-2009-0021 http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327 http://www.sudo.ws/cgi-bin/cvsweb/sudo/parse.c.diff?r1=1.160.2.21&r2=1.160.2.22&f=h http://www.vmware.com/security/advisories/VMSA-2009-0009.html https://bugzilla.novell.com/show_bug.cgi?id=468923 https://issues.rpath.com/browse/RPL-2954 oval:org.mitre.oval:def:10856 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10856 oval:org.mitre.oval:def:6462 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6462 |
Copyright | Copyright (C) 2009 E-Soft Inc. |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |