[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2642-1 sudo -- several issues

ID: oval:org.secpod.oval:def:600985Date: (C)2013-03-14   (M)2023-12-07
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in sudo, a program designed to allow a sysadmin to give limited root privileges to users. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-1775 Marco Schoepl discovered an authentication bypass when the clock is set to the UNIX epoch [00:00:00 UTC on 1 January 1970]. CVE-2013-1776 Ryan Castellucci and James Ogden discovered aspects of an issue that would allow session id hijacking from another authorized tty.

Platform:
Debian 6.0
Product:
sudo
Reference:
DSA-2642-1
CVE-2013-1775
CVE-2013-1776
CVE    2
CVE-2013-1776
CVE-2013-1775
CPE    81
cpe:/a:todd_miller:sudo:1.6
cpe:/a:todd_miller:sudo:1.6.8
cpe:/a:todd_miller:sudo:1.8.6
cpe:/a:todd_miller:sudo:1.6.7
...

© SecPod Technologies