Oval Definition:oval:org.opensuse.security:def:78484
Revision Date:2016-11-24Version:1
Title:Security update for sudo (Moderate)
Description:



This update for sudo fixes the following security issues:

- Fix two security vulnerabilities that allowed users to bypass sudo's NOEXEC functionality: * noexec bypass via system() and popen() [CVE-2016-7032, bsc#1007766] * noexec bypass via wordexp() [CVE-2016-7076, bsc#1007501] - Fix unsafe handling of TZ environment variable. [CVE-2014-9680, bsc#917806]

Additionally, these non-security fixes are included in the update:

- Fix 'ignoring time stamp from the future' message after each boot with !tty_tickets. [bsc#899252] - Enable support for SASL-based authentication. [bsc#979531]
Family:unixClass:patch
Status:Reference(s):1007501
1007766
899252
917806
979531
CVE-2014-9680
CVE-2016-7032
CVE-2016-7076
SUSE-SU-2016:2904-1
Platform(s):SUSE Linux Enterprise Desktop 12 SP1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND sudo-1.8.10p3-2.6.1 is installed
  • BACK