Executive Summary
Summary | |
---|---|
Title | New sudo packages for powerpc available |
Informations | |||
---|---|---|---|
Name | DSA-031 | First vendor Publication | 2001-02-28 |
Vendor | Debian | Last vendor Modification | 2001-03-06 |
Severity (Vendor) | N/A | Revision | 2 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.2 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Todd Miller announced a new version of sudo which corrects a buffer overflow that could potentially be used to gain root privilages on the local system. This bugfix has been backported to the version which was used in Debian GNU/Linux 2.2. The most recent advisory covering sudo missed one architecture that was released with 2.2. Therefore this advisory is only an addition to DSA 031-1 and only adds the relevant package for the powerpc architecture. We recommend you upgrade your sudo packages for powerpc immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato |
Original Source
Url : http://www.debian.org/security/2001/dsa-031 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 | |
Os | 2 | |
Os | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2008-01-17 | Name : Debian Security Advisory DSA 031-1 (sudo) File : nvt/deb_031_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
5688 | sudo Long Argument Local Overflow A local overflow exists in sudo utility. The sudo version prior to 1.63p6 fails to split a log entry into smaller pieces resulting in a buffer overflow. By sending a specially crafted long command to sudo, an attacker can overflow a buffer and execute arbitrary commands with root privileges resulting in a loss of confidentiality, integrity, and confidentiality. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2012-09-06 | Name : The remote Mandrake Linux host is missing a security update. File : mandrake_MDKSA-2001-024.nasl - Type : ACT_GATHER_INFO |
2004-09-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-031.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:25:20 |
|