Advisories ยป MGASA-2016-0261

Updated sudo packages fix security vulnerability

Publication date: 26 Jul 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2015-8239


A vulnerability in functionality for adding support of SHA-2 digests along
with the command was found. The sudoers plugin performs this digest
verification while matching rules, and later independently calls execve()
to execute the binary. This results in a race condition if the digest
functionality is used as suggested (in fact, the rules are matched before
the user is prompted for a password, so there is not negligible time frame
to replace the binary from underneath sudo) (CVE-2015-8239).