Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.122174
Categoría:Oracle Linux Local Security Checks
Título:Oracle: Security Advisory (ELSA-2011-0599)
Resumen:The remote host is missing an update for the 'sudo' package(s) announced via the ELSA-2011-0599 advisory.
Descripción:Summary:
The remote host is missing an update for the 'sudo' package(s) announced via the ELSA-2011-0599 advisory.

Vulnerability Insight:
[1.7.4p5-5]
- patch: log failed user role changes
Resolves: rhbz#665131

[1.7.4p5-4]
- added #includedir /etc/sudoers.d to sudoers
Resolves: rhbz#615087

[1.7.4p5-3]
- added !visiblepw option to sudoers
Resolves: rhbz#688640

[1.7.4p5-2]
- added patch for rhbz#665131
Resolves: rhbz#665131

[1.7.4p5-1]
- rebase to latest stable version
- sudo now uses /var/db/sudo for timestamps
- new command available: sudoreplay
- use native audit support
- sync configuration paths with the nss_ldap package
Resolves: rhbz#615087
Resolves: rhbz#652726
Resolves: rhbz#634159
Resolves: rhbz#603823

Affected Software/OS:
'sudo' package(s) on Oracle Linux 6.

Solution:
Please install the updated package(s).

CVSS Score:
4.4

CVSS Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-0010
42886
http://secunia.com/advisories/42886
42949
http://secunia.com/advisories/42949
42968
http://secunia.com/advisories/42968
43068
http://secunia.com/advisories/43068
43282
http://secunia.com/advisories/43282
45774
http://www.securityfocus.com/bid/45774
70400
http://www.osvdb.org/70400
ADV-2011-0089
http://www.vupen.com/english/advisories/2011/0089
ADV-2011-0182
http://www.vupen.com/english/advisories/2011/0182
ADV-2011-0195
http://www.vupen.com/english/advisories/2011/0195
ADV-2011-0199
http://www.vupen.com/english/advisories/2011/0199
ADV-2011-0212
http://www.vupen.com/english/advisories/2011/0212
ADV-2011-0362
http://www.vupen.com/english/advisories/2011/0362
FEDORA-2011-0455
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053341.html
FEDORA-2011-0470
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053263.html
GLSA-201203-06
http://security.gentoo.org/glsa/glsa-201203-06.xml
MDVSA-2011:018
http://www.mandriva.com/security/advisories?name=MDVSA-2011:018
RHSA-2011:0599
http://www.redhat.com/support/errata/RHSA-2011-0599.html
SSA:2011-041-05
http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.593654
SUSE-SR:2011:002
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
USN-1046-1
http://www.ubuntu.com/usn/USN-1046-1
[oss-security] 20110111 CVE request: sudo does not ask for password on GID changes
http://openwall.com/lists/oss-security/2011/01/11/3
[oss-security] 20110112 Re: CVE request: sudo does not ask for password on GID changes
http://openwall.com/lists/oss-security/2011/01/12/1
http://openwall.com/lists/oss-security/2011/01/12/3
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=609641
http://www.sudo.ws/repos/sudo/rev/07d1b0ce530e
http://www.sudo.ws/repos/sudo/rev/fe8a94f96542
http://www.sudo.ws/sudo/alerts/runas_group_pw.html
https://bugzilla.redhat.com/show_bug.cgi?id=668879
sudo-groupid-privilege-escalation(64636)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64636
CopyrightCopyright (C) 2015 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.