LINUX LITE 7.2 FINAL RELEASED - SEE RELEASE ANNOUNCEMENTS SECTION FOR DETAILS


Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
SUDO Flaw CVE-2017-1000367 Series 2.x Series 3.x
#1
A high-severity vulnerability has been reported in Linux that could be exploited by a low privilege attacker to gain full root access on an affected system.
The vulnerability, identified as CVE-2017-1000367, was discovered by researchers at Qualys Security in Sudo's "get_process_ttyname()" function for Linux that could allow a user with Sudo privileges to run commands as root or elevate privileges to root.

1. Make sure to run Menu, Favorites, Install Updates.

2. Open a terminal:

Code:
apt policy sudo

should show the patched version for Series 3.x:

Code:
apt policy sudo
sudo:
  Installed: 1.8.16-0ubuntu1.4
  Candidate: 1.8.16-0ubuntu1.4

should show the patched version for Series 2.x:

Code:
apt policy sudo
sudo:
  Installed: 1.8.9p5-1ubuntu1.4
  Candidate: 1.8.9p5-1ubuntu1.4

Sources:

https://people.canonical.com/~ubuntu-sec...00367.html

http://thehackernews.com/2017/05/linux-s...-hack.html
Reply


Messages In This Thread
SUDO Flaw CVE-2017-1000367 Series 2.x Series 3.x - by Valtam - 06-02-2017, 03:19 AM

Forum Jump:


Users browsing this thread: 5 Guest(s)