Vulnerability Bulletins

DSA-3167 sudo - security update

   
Affected software Debian
 
Jakub Wilk reported that sudo, a program designed to provide limitedsuper user privileges to specific users, preserves the TZ variable froma users environment without any sanitization. A user with sudo accessmay take advantage of this to exploit bugs in the C library functionswhich parse the TZ environment variable or to open files that the userwould not otherwise be able to open. The later could potentially causechanges in system behavior when reading certain device special files orcause the

More info:

https://www.debian.org/security/2015/dsa-3167