Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.702642
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2642-1)
Summary:The remote host is missing an update for the Debian 'sudo' package(s) announced via the DSA-2642-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'sudo' package(s) announced via the DSA-2642-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been discovered in sudo, a program designed to allow a sysadmin to give limited root privileges to users. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2013-1775

Marco Schoepl discovered an authentication bypass when the clock is set to the UNIX epoch [00:00:00 UTC on 1 January 1970].

CVE-2013-1776

Ryan Castellucci and James Ogden discovered aspects of an issue that would allow session id hijacking from another authorized tty.

For the stable distribution (squeeze), these problems have been fixed in version 1.7.4p4-2.squeeze.4.

For the testing (wheezy) and unstable (sid) distributions, these problems have been fixed in version 1.8.5p2-1+nmu1.

We recommend that you upgrade your sudo packages.

Affected Software/OS:
'sudo' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
6.9

CVSS Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-1775
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
BugTraq ID: 58203
http://www.securityfocus.com/bid/58203
Debian Security Information: DSA-2642 (Google Search)
http://www.debian.org/security/2013/dsa-2642
http://www.openwall.com/lists/oss-security/2013/02/27/22
http://osvdb.org/90677
RedHat Security Advisories: RHSA-2013:1353
http://rhn.redhat.com/errata/RHSA-2013-1353.html
RedHat Security Advisories: RHSA-2013:1701
http://rhn.redhat.com/errata/RHSA-2013-1701.html
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2013&m=slackware-security.517440
SuSE Security Announcement: openSUSE-SU-2013:0495 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-03/msg00066.html
http://www.ubuntu.com/usn/USN-1754-1
Common Vulnerability Exposure (CVE) ID: CVE-2013-1776
BugTraq ID: 58207
http://www.securityfocus.com/bid/58207
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=701839
https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/87023
https://bugzilla.redhat.com/show_bug.cgi?id=916365
http://www.openwall.com/lists/oss-security/2013/02/27/31
XForce ISS Database: sudo-ttytickets-sec-bypass(82453)
https://exchange.xforce.ibmcloud.com/vulnerabilities/82453
Common Vulnerability Exposure (CVE) ID: CVE-2013-2776
BugTraq ID: 62741
http://www.securityfocus.com/bid/62741
Common Vulnerability Exposure (CVE) ID: CVE-2013-2777
CopyrightCopyright (C) 2013 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.