sudo-1.7.4p5-7.AXS4

エラータID: AXSA:2011-635:01

リリース日: 
2011/12/28 Wednesday - 12:19
題名: 
sudo-1.7.4p5-7.AXS4
影響のあるチャネル: 
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity: 
High
Description: 

Sudo (superuser do) allows a system administrator to give certain users (or groups of users) the ability to run some (or all) commands as root while logging all commands and arguments. Sudo operates on a per-command basis. It is not a replacement for the shell. Features include: the ability to restrict what commands a user may run on a per-host basis, copious logging of each command (providing a clear audit trail of who did what), a configurable timeout of the sudo command, and the ability to use the same configuration file (sudoers) on many different machines.
Security issues fixed with this release:
CVE-2011-0010
check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.
Fixed bugs:
- With "/etc/sudoers" files containing several host entries, the "sudo -l" command incorrectly reported that a certain user does not have permissions to use sudo on the system. This has been fixed.
- the manual page for sudoers.ldap is now properly included in the package. Additionally, various POD files only needed for building purposes have been removed from the package
- sudo now uses the same location for the LDAP configuration files as the nss_ldap package, in the /etc/nslcd.conf file.
- When editing a file with the "sudo -e file" or the "sudoedit file" command, the editor was logged only as "sudoedit". The full path to the executable being used as an editor is now logged.
- Added a comment regarding the "visiblepw" option of the "Defaults" directive to the default "/etc/sudoers" file to clarify its usage.
- Upgraded sudo to upstream version 1.7.4p5, which provides many bug fixes and enhancements.
Enhancement:
- The sudo package is now built with RELRO linker flags because it needs to be run with elevated privileges.

解決策: 

Update packages.

追加情報: 

From Asianux Server 4 SP1.

ダウンロード: 

SRPMS
  1. sudo-1.7.4p5-7.AXS4.src.rpm
    MD5: a73e1d8ba10b10976dca9d4edad493b2
    SHA-256: 7da3674e4c974a9ca1ff0d408fe176f519ee7c1bb0d50e1da882bf45b58843df
    Size: 972.62 kB

Asianux Server 4 for x86
  1. sudo-1.7.4p5-7.AXS4.i686.rpm
    MD5: 317fd32f9ff6905775078efa5f2e58c1
    SHA-256: 5d604227103d224f4884b0ea780683d47a780abaf88a44a8aa6511f631c5f4aa
    Size: 413.41 kB

Asianux Server 4 for x86_64
  1. sudo-1.7.4p5-7.AXS4.x86_64.rpm
    MD5: c34ba4216e11ce4abe789ad11b8be114
    SHA-256: ad6f7d72b42bd6523a5cf7cab48f3c079428b81be46f267f2b890d7f70f5300b
    Size: 416.89 kB