Lucene search

K
suseSuseSUSE-SA:2002:002
HistoryJan 14, 2002 - 12:29 p.m.

local privilege escalation in sudo

2002-01-1412:29:16
lists.opensuse.org
6

EPSS

0

Percentile

0.4%

The SuSE Security Team discovered a bug in the sudo program which is installed setuid to root. Attackers may trick “sudo” to log failed sudo invocations executing the sendmail program with root-privileges and not completely cleaned environment. Depending on the installed mail-package this may enable attackers to execute code as root. This is the case for at least the postfix mailer. Other mailers may be exploited in a similar way. This bug has been fixed by having “sudo” invoke the sendmail command with user-privileges instead. Please update your sudo package regardless of the mail-packages you are using. As a temporary workaround you may remove the s-bit from sudo with the “chmod -s which sudo” command, which will disable the sudo functionality.

EPSS

0

Percentile

0.4%

Related for SUSE-SA:2002:002