![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.870711 |
Category: | Red Hat Local Security Checks |
Title: | RedHat Update for sudo RHSA-2011:0599-01 |
Summary: | The remote host is missing an update for the 'sudo'; package(s) announced via the referenced advisory. |
Description: | Summary: The remote host is missing an update for the 'sudo' package(s) announced via the referenced advisory. Vulnerability Insight: The sudo (superuser do) utility allows system administrators to give certain users the ability to run commands as root. A flaw was found in the sudo password checking logic. In configurations where the sudoers settings allowed a user to run a command using sudo with only the group ID changed, sudo failed to prompt for the user's password before running the specified command with the elevated group privileges. (CVE-2011-0010) This update also fixes the following bugs: * When the '/etc/sudoers' file contained entries with multiple hosts, running the 'sudo -l' command incorrectly reported that a certain user does not have permissions to use sudo on the system. With this update, running the 'sudo -l' command now produces the correct output. (BZ#603823) * Prior to this update, the manual page for sudoers.ldap was not installed, even though it contains important information on how to set up an LDAP (Lightweight Directory Access Protocol) sudoers source, and other documents refer to it. With this update, the manual page is now properly included in the package. Additionally, various POD files have been removed from the package, as they are required for build purposes only. (BZ#634159) * The previous version of sudo did not use the same location for the LDAP configuration files as the nss_ldap package. This has been fixed and sudo now looks for these files in the same location as the nss_ldap package. (BZ#652726) * When a file was edited using the 'sudo -e file' or the 'sudoedit file' command, the editor being executed for this task was logged only as 'sudoedit'. With this update, the full path to the executable being used as an editor is now logged (instead of 'sudoedit'). (BZ#665131) * A comment regarding the 'visiblepw' option of the 'Defaults' directive has been added to the default '/etc/sudoers' file to clarify its usage. (BZ#688640) * This erratum upgrades sudo to upstream version 1.7.4p5, which provides a number of bug fixes and enhancements over the previous version. (BZ#615087) All users of sudo are advised to upgrade to this updated package, which resolves these issues. Affected Software/OS: sudo on Red Hat Enterprise Linux Desktop (v. 6), Red Hat Enterprise Linux Server (v. 6), Red Hat Enterprise Linux Workstation (v. 6) Solution: Please Install the Updated Packages. CVSS Score: 4.4 CVSS Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2011-0010 42886 http://secunia.com/advisories/42886 42949 http://secunia.com/advisories/42949 42968 http://secunia.com/advisories/42968 43068 http://secunia.com/advisories/43068 43282 http://secunia.com/advisories/43282 45774 http://www.securityfocus.com/bid/45774 70400 http://www.osvdb.org/70400 ADV-2011-0089 http://www.vupen.com/english/advisories/2011/0089 ADV-2011-0182 http://www.vupen.com/english/advisories/2011/0182 ADV-2011-0195 http://www.vupen.com/english/advisories/2011/0195 ADV-2011-0199 http://www.vupen.com/english/advisories/2011/0199 ADV-2011-0212 http://www.vupen.com/english/advisories/2011/0212 ADV-2011-0362 http://www.vupen.com/english/advisories/2011/0362 FEDORA-2011-0455 http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053341.html FEDORA-2011-0470 http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053263.html GLSA-201203-06 http://security.gentoo.org/glsa/glsa-201203-06.xml MDVSA-2011:018 http://www.mandriva.com/security/advisories?name=MDVSA-2011:018 RHSA-2011:0599 http://www.redhat.com/support/errata/RHSA-2011-0599.html SSA:2011-041-05 http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.593654 SUSE-SR:2011:002 http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html USN-1046-1 http://www.ubuntu.com/usn/USN-1046-1 [oss-security] 20110111 CVE request: sudo does not ask for password on GID changes http://openwall.com/lists/oss-security/2011/01/11/3 [oss-security] 20110112 Re: CVE request: sudo does not ask for password on GID changes http://openwall.com/lists/oss-security/2011/01/12/1 http://openwall.com/lists/oss-security/2011/01/12/3 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=609641 http://www.sudo.ws/repos/sudo/rev/07d1b0ce530e http://www.sudo.ws/repos/sudo/rev/fe8a94f96542 http://www.sudo.ws/sudo/alerts/runas_group_pw.html https://bugzilla.redhat.com/show_bug.cgi?id=668879 sudo-groupid-privilege-escalation(64636) https://exchange.xforce.ibmcloud.com/vulnerabilities/64636 |
Copyright | Copyright (C) 2012 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |