Get a Pentest and security assessment of your IT network.

Advisories

Mandriva Linux Security Advisory 2010-078

Mandriva Linux Security Advisory 2010-078 – The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for., which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct this issue.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/88623/MDVSA-2010-078.txt

Source: https://packetstormsecurity.com/files/88623/Mandriva-Linux-Security-Advisory-2010-078.html

Related posts
Advisories

Secunia Security Advisory 16074

Advisories

Secunia Security Advisory 19116

Advisories

Secunia Security Advisory 21833

Advisories

Ubuntu Security Notice 451-1