Oval Definition:oval:com.ubuntu.precise:def:20140106000
Revision Date:2014-03-11Version:1
Title:CVE-2014-0106 on Ubuntu 12.04 LTS (precise) - medium.
Description:Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-0106
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'sudo' package in precise was vulnerable but has been fixed (note: '1.8.3p1-1ubuntu3.6').
  • BACK