Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <201101122056.p0CKuOsj006751@core.courtesan.com>
Date: Wed, 12 Jan 2011 15:56:23 -0500
From: "Todd C. Miller" <Todd.Miller@...rtesan.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: sudo does not ask for password on GID changes

On Tue, 11 Jan 2011 15:52:46 MST, Vincent Danen wrote:

> A Debian bug report noted that sudo does not access for a password on
> GID changes, like it does for UID changes.  This could allow a user to
> execute commands using '-g [group]' without being prompted for their
> password.

This is fixed in sudo 1.7.4p5, available now.

I've written up details of the bug in:
    http://www.sudo.ws/sudo/alerts/runas_group_pw.html

 - todd

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.