Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Scientific Linux: CVE-2009-0034 Moderate Sudo Security Update for SL5.x

Scientific Large Esm H446
Moderate: sudo security update
Date: Wed, 4 Feb 2009 14:19:09 -0600
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: FASTBUGS for SL 4.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 

The following FASTBUGS have been uploaded to

 i386:
jwhois-3.2.2-15.el4.i386.rpm
kdenetwork-3.3.1-4.el4.i386.rpm
kdenetwork-devel-3.3.1-4.el4.i386.rpm
kdenetwork-nowlistening-3.3.1-4.el4.i386.rpm
PyQt-3.13-2.el4.i386.rpm
PyQt-devel-3.13-2.el4.i386.rpm
PyQt-examples-3.13-2.el4.i386.rpm
qt-3.3.3-16.el4.i386.rpm
qt-config-3.3.3-16.el4.i386.rpm
qt-designer-3.3.3-16.el4.i386.rpm
qt-devel-3.3.3-16.el4.i386.rpm
qt-MySQL-3.3.3-16.el4.i386.rpm
qt-ODBC-3.3.3-16.el4.i386.rpm
qt-PostgreSQL-3.3.3-16.el4.i386.rpm
system-config-printer-0.6.116.10-1.4.el4.i386.rpm
system-config-printer-gui-0.6.116.10-1.4.el4.i386.rpm
traceroute-1.4a12-27.EL4.1.i386.rpm
xemacs-21.4.15-15.EL4.i386.rpm
xemacs-common-21.4.15-15.EL4.i386.rpm
xemacs-el-21.4.15-15.EL4.i386.rpm
xemacs-info-21.4.15-15.EL4.i386.rpm
xemacs-nox-21.4.15-15.EL4.i386.rpm
xemacs-sumo-20040818-3.noarch.rpm
xemacs-sumo-el-20040818-3.noarch.rpm
xemacs-sumo-info-20040818-3.noarch.rpm

 x86_64:
jwhois-3.2.2-15.el4.x86_64.rpm
kdenetwork-3.3.1-4.el4.x86_64.rpm
kdenetwork-devel-3.3.1-4.el4.x86_64.rpm
kdenetwork-nowlistening-3.3.1-4.el4.x86_64.rpm
PyQt-3.13-2.el4.x86_64.rpm
PyQt-devel-3.13-2.el4.x86_64.rpm
PyQt-examples-3.13-2.el4.x86_64.rpm
qt-3.3.3-16.el4.i386.rpm
qt-3.3.3-16.el4.x86_64.rpm
qt-config-3.3.3-16.el4.x86_64.rpm
qt-designer-3.3.3-16.el4.x86_64.rpm
qt-devel-3.3.3-16.el4.x86_64.rpm
qt-MySQL-3.3.3-16.el4.x86_64.rpm
qt-ODBC-3.3.3-16.el4.x86_64.rpm
qt-PostgreSQL-3.3.3-16.el4.x86_64.rpm
system-config-printer-0.6.116.10-1.4.el4.x86_64.rpm
system-config-printer-gui-0.6.116.10-1.4.el4.x86_64.rpm
traceroute-1.4a12-27.EL4.1.x86_64.rpm
xemacs-21.4.15-15.EL4.x86_64.rpm
xemacs-common-21.4.15-15.EL4.x86_64.rpm
xemacs-el-21.4.15-15.EL4.x86_64.rpm
xemacs-info-21.4.15-15.EL4.x86_64.rpm
xemacs-nox-21.4.15-15.EL4.x86_64.rpm
xemacs-sumo-20040818-3.noarch.rpm
xemacs-sumo-el-20040818-3.noarch.rpm
xemacs-sumo-info-20040818-3.noarch.rpm

-Connie Sieh
-Troy Dawson
Date: Thu, 5 Feb 2009 15:03:08 -0600
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: Security ERRATA Moderate: sudo on SL5.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 

Synopsis:	Moderate: sudo security update
Issue date:	2009-02-05
CVE Names:	CVE-2009-0034

A flaw was discovered in a way sudo handled group specifications in "run
as" lists in the sudoers configuration file. If sudo configuration
allowed a user to run commands as any user of some group and the user
was also a member of that group, sudo incorrectly allowed them to run
defined commands with the privileges of any system user. This gave the
user unintended privileges. (CVE-2009-0034)

SL 5.x

 SRPMS:
sudo-1.6.9p17-3.el5_3.1.src.rpm
 i386:
sudo-1.6.9p17-3.el5_3.1.i386.rpm
 x86_64:
sudo-1.6.9p17-3.el5_3.1.x86_64.rpm

-Connie Sieh
-Troy Dawson