Ubuntu Security Notice USN-722-1 – Harald Koenig discovered that sudo did not correctly handle certain privilege changes when handling groups. If a local attacker belonged to a group included in a “RunAs” list in the /etc/sudoers file, that user could gain root privileges. This was not an issue for the default sudoers file shipped with Ubuntu.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/75011/USN-722-1.txt
Source: https://packetstormsecurity.com/files/75011/Ubuntu-Security-Notice-722-1.html

