Vulnerability Bulletins

DSA-3440 sudo - security update

   
Affected software Debian
 
When sudo is configured to allow a user to edit files under a directorythat they can already write to without using sudo, they can actuallyedit (read and write) arbitrary files. Daniel Svartman reported that aconfiguration like this might be introduced unintentionally if theeditable files are specified using wildcards, for example:

More info:

https://www.debian.org/security/2016/dsa-3440