Advisories Blog | G5 Cyber Security

Ubuntu Security Notice 956-1

Ubuntu Security Notice 956-1 – Evan Broder and Anders Kaseorg discovered that sudo did not properly sanitize its environment when configured to use secure_path (the default in Ubuntu). A local attacker could exploit this to execute arbitrary code as root if sudo was configured to allow the attacker to use a program that interpreted the PATH environment variable.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/91362/USN-956-1.txt

Source: https://packetstormsecurity.com/files/91362/Ubuntu-Security-Notice-956-1.html

Exit mobile version