Oval Definition:oval:com.redhat.rhba:def:20152424
Revision Date:2015-11-19Version:636
Title:RHBA-2015:2424: sudo bug fix and enhancement update (Moderate)
Description:The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root.

This update fixes the following bug:

  • Previously, the umask_override entry in the sudoers(5) manual page also, incorrectly, contained information on the use_pty flag. With this update, information on the umask_override and usy_pty flags are in separate entries as expected. (BZ#1233607)

    In addition, this update adds the following enhancement:

  • The configuration of the sudo utility can now store the checksum of a command or script that is being permitted. When the command or script is run again, the checksum is compared to the stored checksum to verify that nothing has changed. If the command or binary is modified, the sudo utility refuses to run the command or logs a warning. This functionality makes it possible to correctly devolve responsibility and problem-solving activities if an incident occurs. (BZ#1183818)

    Users of sudo are advised to upgrade to these updated packages, which fix these bugs and add this enhancement.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-9680
    RHBA-2015:2424
    RHBA-2015:2424-02
    RHBA-2015:2424-02
    RHBA-2015:2424
    Platform(s):Red Hat Enterprise Linux 7
    Red Hat Enterprise Linux 7 (please do not use for >= RHEL-7.5)
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • sudo is earlier than 0:1.8.6p7-16.el7
  • AND sudo is signed with Red Hat redhatrelease2 key
  • sudo-devel is earlier than 0:1.8.6p7-16.el7
  • AND sudo-devel is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • AND Package Information
  • sudo is earlier than 0:1.8.6p7-16.el7
  • AND sudo is signed with Red Hat redhatrelease2 key
  • OR
  • sudo-devel is earlier than 0:1.8.6p7-16.el7
  • AND sudo-devel is signed with Red Hat redhatrelease2 key
  • BACK