Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.831637
Category:Mandrake Local Security Checks
Title:Mandriva Update for sudo MDVSA-2012:079 (sudo)
Summary:The remote host is missing an update for the 'sudo'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'sudo'
package(s) announced via the referenced advisory.

Vulnerability Insight:
A vulnerability has been found and corrected in sudo:

A flaw exists in the IP network matching code in sudo versions 1.6.9p3
through 1.8.4p4 that may result in the local host being matched
even though it is not actually part of the network described by the
IP address and associated netmask listed in the sudoers file or in
LDAP. As a result, users authorized to run commands on certain IP
networks may be able to run commands on hosts that belong to other
networks not explicitly listed in sudoers (CVE-2012-2337

The updated packages have been patched to correct this issue.

Affected Software/OS:
sudo on Mandriva Linux 2011.0,
Mandriva Enterprise Server 5.2,
Mandriva Linux 2010.1

Solution:
Please Install the Updated Packages.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-2337
1027077
http://www.securitytracker.com/id?1027077
49219
http://secunia.com/advisories/49219
49244
http://secunia.com/advisories/49244
49291
http://secunia.com/advisories/49291
49948
http://secunia.com/advisories/49948
DSA-2478
http://www.debian.org/security/2012/dsa-2478
FEDORA-2012-7998
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081432.html
MDVSA-2012:079
http://www.mandriva.com/security/advisories?name=MDVSA-2012:079
http://www.sudo.ws/sudo/alerts/netmask.html
https://bugzilla.redhat.com/show_bug.cgi?id=820677
https://www.suse.com/security/cve/CVE-2012-2337/
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.