USN-722-1: sudo vulnerability
17 February 2009
sudo vulnerability
Releases
Packages
- sudo -
Details
Harald Koenig discovered that sudo did not correctly handle certain
privilege changes when handling groups. If a local attacker belonged
to a group included in a "RunAs" list in the /etc/sudoers file, that
user could gain root privileges. This was not an issue for the default
sudoers file shipped with Ubuntu.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 8.10
Ubuntu 8.04
In general, a standard system upgrade is sufficient to effect the
necessary changes.