SUSE-SU-2016:2891-1
Dashboard / Vulnerabilities / SUSE-SU-2016:2891-1
SUSE-SU-2016:2891-1
Summary: Security update for sudo
Details: This update for sudo fixes the following issues: - Fix two security vulnerabilities that allowed users to bypass sudo's NOEXEC functionality: * noexec bypass via system() and popen() [CVE-2016-7032, bsc#1007766] * noexec bypass via wordexp() [CVE-2016-7076, bsc#1007501] - The SSSD plugin would occasionally crash sudo with an 'internal error'. This issue has been fixed. [bsc#948973] - The SSSD plugin would occasionally apply @netgroups rules from LDAP to all users rather than the @netgroup. This issue is now fixed. [bsc#966755] - When the SSSD plugin was used and a local user ran sudo, an e-mail used to be sent to administrator because SSSD did not support sudo rules for local users. This message did not signify an error, however, it was only noise. [bsc#1008043]
References: https://www.suse.com/support/update/announcement/2016/suse-su-20162891-1/, https://bugzilla.suse.com/1007501, https://bugzilla.suse.com/1007766, https://bugzilla.suse.com/1008043, https://bugzilla.suse.com/948973, https://bugzilla.suse.com/966755, https://www.suse.com/security/cve/CVE-2016-7032, https://www.suse.com/security/cve/CVE-2016-7076
Affected packages
Package
Name: sudo
Purl: pkg:rpm/suse/sudo&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
