Mandriva Linux Security Advisory : sudo (MDVSA-2010:175)
Medium Nessus Plugin ID 49205
SynopsisThe remote Mandriva Linux host is missing a security update.
DescriptionA vulnerability has been found and corrected in sudo :
Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a -u root sequence (CVE-2010-2956).
The updated packages have been patched to correct this issue.
SolutionUpdate the affected sudo package.