sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://rhn.redhat.com/errata/RHSA-2016-2872.html | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1372830 | issue tracking vdb entry third party advisory |
https://www.sudo.ws/alerts/noexec_bypass.html | |
http://www.securityfocus.com/bid/95776 | vdb entry third party advisory |
https://usn.ubuntu.com/3968-3/ | vendor advisory |