_______________________________________________________________________
Package : sudo
Date : March 1, 2010
Affected: 2009.0, Enterprise Server 5.0
_______________________________________________________________________
Problem Description:
A vulnerabilitiy has been found and corrected in sudo:
sudo 1.6.x before 1.6.9p21, when the runas_default option is used,
does not properly set group memberships, which allows local users to
gain privileges via a sudo command (CVE-2010-0427).
The updated packages have been patched to correct this issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2010-0427
_______________________________________________________________________