This script is Copyright (C) 2012 Tenable Network Security, Inc.
The remote Scientific Linux host is missing a security update.
A flaw was discovered in a way sudo handled group specifications in
'run as' lists in the sudoers configuration file. If sudo
configuration allowed a user to run commands as any user of some group
and the user was also a member of that group, sudo incorrectly allowed
them to run defined commands with the privileges of any system user.
This gave the user unintended privileges. (CVE-2009-0034)
See also :
Update the affected sudo package.
Risk factor :
Medium / CVSS Base Score : 6.9
Family: Scientific Linux Local Security Checks
Nessus Plugin ID: 60529 ()
CVE ID: CVE-2009-0034