[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2012:079 -- Mandriva sudo

ID: oval:org.secpod.oval:def:302895Date: (C)2012-12-20   (M)2023-12-07
Class: PATCHFamily: unix




A vulnerability has been found and corrected in sudo: A flaw exists in the IP network matching code in sudo versions 1.6.9p3 through 1.8.4p4 that may result in the local host being matched even though it is not actually part of the network described by the IP address and associated netmask listed in the sudoers file or in LDAP. As a result, users authorized to run commands on certain IP networks may be able to run commands on hosts that belong to other networks not explicitly listed in sudoers

Platform:
Mandriva Linux 2011.0
Mandriva Linux 2010.1
Product:
sudo
Reference:
MDVSA-2012:079
CVE-2012-2337
CVE    1
CVE-2012-2337
CPE    2
cpe:/o:mandriva:linux:2010.1
cpe:/o:mandriva:linux:2011.0

© SecPod Technologies