sudo (SSA:2005-172-01)
Posted on: 06/22/2005 05:03 AM
New Sudo packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, and -current to fix a security issue. A race condition could allow a user with Sudo privileges to run arbitrary commands.
Here are the details from the Slackware 10.1 ChangeLog: +--------------------------+ patches/packages/sudo-1.6.8p9-i486-1.tgz: Upgraded to sudo-1.6.8p9. This new version of Sudo fixes a race condition in command pathname handling that could allow a user with Sudo privileges to run arbitrary commands. For full details, see the Sudo site: http://www.courtesan.com/sudo/alerts/path_race.html (* Security fix *) +--------------------------+
Where to find the new packages: +-----------------------------+