exploit the possibilities
Showing 1 - 1 of 1 RSS Feed

Files

Ubuntu Security Notice 928-1
Posted Apr 16, 2010
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 928-1 - Valerio Costamagna discovered that sudo did not properly validate the path for the 'sudoedit' pseudo-command when the PATH contained only a dot ('.'). If secure_path and ignore_dot were disabled, a local attacker could exploit this to execute arbitrary code as root if sudo was configured to allow the attacker to use sudoedit. By default, secure_path is used and the sudoedit pseudo-command is not used in Ubuntu. This is a different but related issue to CVE-2010-0426.

tags | advisory, arbitrary, local, root
systems | linux, ubuntu
MD5 | a5e404d6c6e69d568c75618e1bfc82bc
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
US Stopped Using Floppy Disks To Manage Nuclear Weapons Arsenal
Posted Oct 19, 2019

tags | headline, government, usa, military
Zappos Offers Users 10% Discount In 2012 Breach Settlement
Posted Oct 18, 2019

tags | headline, hacker, privacy, data loss, identity theft
Cryptocurrency Execs Charged With Running $11 Million Ponzi Scheme
Posted Oct 18, 2019

tags | headline, bank, cybercrime, fraud, cryptography
How The Wheels Came Off Facebook's Libra Project
Posted Oct 18, 2019

tags | headline, government, bank, facebook, social, cryptography
Samsung Bug Allows Any Fingerprint To Unlock Phones
Posted Oct 18, 2019

tags | headline, phone, flaw, password, samsung
Dancho Danchev Launches New Uncle George Initiative
Posted Oct 17, 2019

tags | headline, hacker, cybercrime, fraud
Oracle Patches 218 Security Vulnerabilities
Posted Oct 17, 2019

tags | headline, database, flaw, patch, oracle
SHIELD Act Passes Committee
Posted Oct 17, 2019

tags | headline, government, usa, fraud
Cozy Bear Is Back In Action Again
Posted Oct 17, 2019

tags | headline, government, usa, russia, fraud, cyberwar, facebook, social
Cybercrime Tool Prices Bump Up In Dark Web Markets
Posted Oct 17, 2019

tags | headline, hacker, cybercrime, fraud
View More News →
packet storm

© 2019 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close