[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Sudo - (bulletinoct2019)

ID: oval:org.secpod.oval:def:2105121Date: (C)2019-12-30   (M)2023-12-20
Class: PATCHFamily: unix




In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.

Platform:
Sun Solaris 11
Product:
security/sudo
Reference:
bulletinoct2019
CVE-2019-14287
CVE    1
CVE-2019-14287
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies