The remote host is missing an update to sudo announced via advisory USN-1046-1.
Details follow:
Alexander Kurtz discovered that sudo would not prompt for a password when a group was specified in the Runas_Spec. A local attacker could exploit this to execute arbitrary code as the specified group if sudo was configured to allow the attacker to use a program as this group. The group Runas_Spec is not used in the default installation of Ubuntu.
Solution: The problem can be corrected by upgrading your system to the following package versions: