Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Ubuntu 2146-1 Critical Advisory: Sudo Local Attack Risks

ubuntu
Calendar Grey March 13, 2014
Scroller Ubuntu
Multiple vulnerabilities in Sudo have been resolved across various Ubuntu versions. It's vital to update your system right away to ensure security and fend off potential risks
Several security issues were fixed in Sudo.

Summary

Several security issues were fixed in Sudo.

Software Description:

- sudo: Provide limited super user privileges to specific users

Details:

Sebastien Macke discovered that Sudo incorrectly handled blacklisted

environment variables when the env_reset option was disabled. A local

attacker could use this issue to possibly run unintended commands by using

blacklisted environment variables. In a default Ubuntu installation, the

env_reset option is enabled by default. This issue only affected Ubuntu

10.04 LTS and Ubuntu 12.04 LTS. (CVE-2014-0106)

It was discovered that the Sudo init script set a date in the past on

existing timestamp files instead of using epoch to invalidate them

completely. A local attacker could possibly modify the system time to

attempt to reuse timestamp files. This issue only applied to Ubuntu

12.04 LTS, Ubuntu 12.10 and Ubuntu 13.10. (LP: #1223297)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  sudo                            1.8.6p3-0ubuntu3.1
  sudo-ldap                       1.8.6p3-0ubuntu3.1

Ubuntu 12.10:
  sudo                            1.8.5p2-1ubuntu1.2
  sudo-ldap                       1.8.5p2-1ubuntu1.2

Ubuntu 12.04 LTS:
  sudo                            1.8.3p1-1ubuntu3.6
  sudo-ldap                       1.8.3p1-1ubuntu3.6

Ubuntu 10.04 LTS:
  sudo                            1.7.2p1-1ubuntu5.7
  sudo-ldap                       1.7.2p1-1ubuntu5.7

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2146-1

CVE-2014-0106, https://bugs.launchpad.net/ubuntu/+source/sudo/+bug/1223297

Severity
critical
Lowest
Low
Medium
High
Critical

March 13, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.