2015/02/23

『sudo』で security update だって。。@@)

昨日のメールお知らせです。


Package        : sudo
CVE ID         : CVE-2014-9680
Debian Bug     : 772707

Jakub Wilk reported that sudo, a program designed to provide limited
super user privileges to specific users, preserves the TZ variable from
a user's environment without any sanitization. A user with sudo access
may take advantage of this to exploit bugs in the C library functions
which parse the TZ environment variable or to open files that the user
would not otherwise be able to open. The later could potentially cause
changes in system behavior when reading certain device special files or
cause the program run via sudo to block.

For the stable distribution (wheezy), this problem has been fixed in
version 1.8.5p2-1+nmu2.

We recommend that you upgrade your sudo packages.

今朝、update, upgradeしてみると、やはり更新されてます。
sudoって、Linuxの心臓に近い部分じゃん @@)

0 件のコメント:

コメントを投稿