Updated sudo packages fix security vulnerability
Publication date: 26 Jul 2016Modification date: 26 Jul 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2015-8239
Description
A vulnerability in functionality for adding support of SHA-2 digests along with the command was found. The sudoers plugin performs this digest verification while matching rules, and later independently calls execve() to execute the binary. This results in a race condition if the digest functionality is used as suggested (in fact, the rules are matched before the user is prompted for a password, so there is not negligible time frame to replace the binary from underneath sudo) (CVE-2015-8239).
References
SRPMS
5/core
- sudo-1.8.17p1-1.mga5