code is just a tactic
Showing 1 - 1 of 1 RSS Feed

Files

Ubuntu Security Notice 983-1
Posted Sep 8, 2010
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 983-1 - Markus Wuethrich discovered that sudo did not always verify the user when a group was specified in the Runas_Spec. A local attacker could exploit this to execute arbitrary code as root if sudo was configured to allow the attacker to use a program as a group when the attacker was not a part of that group.

tags | advisory, arbitrary, local, root
systems | linux, ubuntu
advisories | CVE-2010-2956
MD5 | 208cd1d61b0cdf3a03dd8f94bf34ed01
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close