|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2005-1993: sudo is vulnerable to a race condition | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Thomas Biege <thomas> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P2 - High | CC: | nadvornik, patch-request, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | All | ||
| Whiteboard: | CVE-2005-1993: CVSS v2 Base Score: 3.7 (AV:L/AC:H/Au:N/C:P/I:P/A:P) | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: |
sudo-test.sh
sudo.diff |
||
|
Description
Thomas Biege
2005-06-21 07:00:42 UTC
To: Josh Bressers <bressers@redhat.com> Cc: vendor-sec@lst.de Subject: Re: [vendor-sec] Sudo version 1.6.8p9 now available, fixes security issue. From: "Todd C. Miller" <Todd.Miller@courtesan.com> Errors-To: vendor-sec-admin@lst.de Date: Mon, 20 Jun 2005 10:16:07 -0600 In message <20050620160823.GR28017@devserv.devel.redhat.com> so spake Josh Bressers (bressers): > The details of this issue have me confused. Does the user have to be able > to create a symlink anywhere on the disk, or in a privileged location (ie > /usr/bin)? Anywhere. - todd _______________________________________________ Vendor Security mailing list ====================================================== Candidate: CAN-2005-1993 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1993 Reference: BUGTRAQ:20050620 Sudo version 1.6.8p9 now available, fixes security issue. Reference: URL:http://www.securityfocus.com/archive/1/402741 Reference: CONFIRM:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161116 Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack. Created attachment 39552 [details]
sudo-test.sh
demo exploit
test case
Created attachment 39553 [details]
sudo.diff
SM-Tracker-1615 major... please provide fix within the next days Marian? are you there? fixes submited Thanks! /work/src/done/PATCHINFO/sudo.patch.maintained /work/src/done/PATCHINFO/sudo.patch.box packages approved, will release advisory ASAP. CVE-2005-1993: CVSS v2 Base Score: 3.7 (AV:L/AC:H/Au:N/C:P/I:P/A:P) |