Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.1.2.2015.160
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DLA-160-1)
Summary:The remote host is missing an update for the Debian 'sudo' package(s) announced via the DLA-160-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'sudo' package(s) announced via the DLA-160-1 advisory.

Vulnerability Insight:
This update fixes the CVEs described below.

CVE-2014-0106

Todd C. Miller reported that if the env_reset option is disabled in the sudoers file, the env_delete option is not correctly applied to environment variables specified on the command line. A malicious user with sudo permissions may be able to run arbitrary commands with elevated privileges by manipulating the environment of a command the user is legitimately allowed to run.

CVE-2014-9680

Jakub Wilk reported that sudo preserves the TZ variable from a user's environment without any sanitization. A user with sudo access may take advantage of this to exploit bugs in the C library functions which parse the TZ environment variable or to open files that the user would not otherwise be able to open. The latter could potentially cause changes in system behavior when reading certain device special files or cause the program run via sudo to block.

For the oldstable distribution (squeeze), these problems have been fixed in version 1.7.4p4-2.squeeze.5.

For the stable distribution (wheezy), they have been fixed in version 1.8.5p2-1+nmu2.

We recommend that you upgrade your sudo packages.

Affected Software/OS:
'sudo' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
6.6

CVSS Vector:
AV:L/AC:M/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-0106
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
BugTraq ID: 65997
http://www.securityfocus.com/bid/65997
http://www.openwall.com/lists/oss-security/2014/03/06/2
RedHat Security Advisories: RHSA-2014:0266
http://rhn.redhat.com/errata/RHSA-2014-0266.html
SuSE Security Announcement: SUSE-SU-2014:0475 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00003.html
http://www.ubuntu.com/usn/USN-2146-1
Common Vulnerability Exposure (CVE) ID: CVE-2014-9680
https://security.gentoo.org/glsa/201504-02
http://openwall.com/lists/oss-security/2014/10/15/24
RedHat Security Advisories: RHSA-2015:1409
http://rhn.redhat.com/errata/RHSA-2015-1409.html
http://www.securitytracker.com/id/1033158
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.