[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2012-110 --- sudo

ID: oval:org.secpod.oval:def:1601290Date: (C)2020-11-27   (M)2021-11-08
Class: PATCHFamily: unix




A flaw was found in the way the network matching code in sudo handled multiple IP networks listed in user specification configuration directives. A user, who is authorized to run commands with sudo on specific hosts, could use this flaw to bypass intended restrictions and run those commands on hosts not matched by any of the network specifications

Platform:
Amazon Linux AMI
Product:
sudo
Reference:
ALAS-2012-110
CVE-2012-2337
CVE    1
CVE-2012-2337
CPE    21
cpe:/o:amazon:linux
cpe:/a:todd_miller:sudo:1.6
cpe:/a:todd_miller:sudo:1.6.8
cpe:/a:todd_miller:sudo:1.6.7
...

© SecPod Technologies