Boletines de Vulnerabilidades

DSA-3867 sudo - security update

   
Software afectado Debian
 
The Qualys Security team discovered that sudo, a program designed toprovide limited super user privileges to specific users, does notproperly parse "/proc/[pid]/stat" to read the device number of the ttyfrom field 7 (tty_nr). A sudoers user can take advantage of this flaw onan SELinux-enabled system to obtain full root privileges.

More info:

https://www.debian.org/security/2017/dsa-3867