Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Todd Miller Sudo Local Race Condition Vulnerability

Sudo is prone to a local race-condition vulnerability. The issue manifests itself only under certain conditions, specifically, when the 'sudoers' configuration file contains a pseudo-command 'ALL' that directly follows a user's 'sudoers' entry.

When such a configuration exists, local attackers may leverage this issue to execute arbitrary executables with escalated privileges. Attackers may achieve this by creating symbolic links to target files.







 

Privacy Statement
Copyright 2009, SecurityFocus