close
Pourquoi s'enregistré ... Pour bénéficié de plein d'avantage, plus l'accès à des partis du site qui ne sont accessible qu'aux membres. L'inscription n'est pas une obligation.

       
Mot de passe oublié?    Identifiant oublié?    Créer un compte

Si toute fois vous avez envies de vous inscrire, donner une adresse e-mail valide, car il vous seras envoyer un mail de confirmation d'ouverture de compte. Merci.
Top Panel
Login
Top Panel

Pin-Up

Recherche Google

Publicité

MDVSA-2011:018: sudo PDF Imprimer Envoyer
(0 Votes)
Écrit par Administrator   
Mercredi, 02 Février 2011 00:00
Multiple vulnerabilities has been found and corrected in sudo:

A a patch for parse.c in sudo does not properly interpret a system
group (aka %group) in the sudoers file during authorization decisions
for a user who belongs to that group, which allows local users to
leverage an applicable sudoers file and gain root privileges via a sudo
command. NOTE: this vulnerability exists because of a CVE-2009-0034
regression (CVE-2011-0008).

check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured,
does not require a password for command execution that involves a
gid change but no uid change, which allows local users to bypass an
intended authentication requirement via the -g option to a sudo command
(CVE-2011-0010).

Packages for 2009.0 are provided as of the Extended Maintenance
Program. Please visit this link to learn more:
http://store.mandriva.com/product_info.php?cPath=149&products_id=490

The updated packages have been upgraded to the latest versions
(1.7.4p6) which is not affected by these issues.

Lire la suite...

 

Ajouter un Commentaire


Code de sécurité
Rafraîchir

maps.amung.us

www.geo-loc.com

Publicité

Browse the web faster with Firefox