Frugalware Let's make things frugal!
En Fr Es It
Package:sudo
Date:2015-03-02
Posted by:kikadf
Vulnerable version:1.8.9-1
Unaffected version:1.8.12-1rigel2
Bug tracker entry:
CVEs:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9680
Description:Jakub Wilk reported that sudo, a program designed to provide limited super user privileges to specific users, preserves the TZ variable from a user's environment without any sanitization. A user with sudo access may take advantage of this to exploit bugs in the C library functions which parse the TZ environment variable or to open files that the user would not otherwise be able to open. The later could potentially cause changes in system behavior when reading certain device special files or cause the program run via sudo to block.