Boletines de Vulnerabilidades |
DSA-3867 sudo - security update |
|
| Software afectado | Debian |
|
The Qualys Security team discovered that sudo, a program designed toprovide limited super user privileges to specific users, does notproperly parse "/proc/[pid]/stat" to read the device number of the ttyfrom field 7 (tty_nr). A sudoers user can take advantage of this flaw onan SELinux-enabled system to obtain full root privileges. More info: https://www.debian.org/security/2017/dsa-3867 |
|














