Skip to main content

sudo bug fix update

Updated sudo packages that fix two bugs are now available for Red Hat Enterprise
Linux 6.
The sudo (superuser do) utility allows system administrators to give certain
users the ability to run commands as root.

This update fixes the following bugs:

* A race condition in the signal handling code caused the sudo process to become
unresponsive after receiving the SIGCHLD signal. This update modifies the signal
handling to prevent the race condition, which ensures that the sudo process no
longer hangs under these circumstances. (BZ#802440)

* The "-l" option is used to list allowed and forbidden commands for the
invoking user or for the user specified by the "-U" option. However, previously,
the getgrouplist() function incorrectly checked the invoker's group membership
instead of the membership of the specified user. Consequently, using the "sudo"
command with both the "-l" and "-U" options listed privileges granted to any
group the invoker was a member of. The getgrouplist() function has been fixed to
properly check the group membership of the intended user rather than checking
the invoker's membership. This ensures that the required output is listed when
using the "-l" and "-U options. (BZ#811879)

All users of sudo are advised to upgrade to these updated packages, which fix
these bugs.

Solution

Before applying this update, make sure that all previously-released errata
relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use the Red Hat
Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259


Original article

Comments

Popular posts from this blog

Feedly launches 'Feedly Cloud' sync platform, new web interface

Feedly, one of the leading Google Reader replacement services, announced major restructuring of its services today with a new cloud infrastructure and web interface. Posted on its official blog, Feedly unveiled what it calls "Feedly Cloud", a scalable infrastructure it says is ready to replace Google Reader. The new Feedly Cloud provides several benefits, the first of which is one-click import from Google Reader -- new users to the service can now simply pull everything over seamlessly from their Google account and start using Feedly right away. Existing users will simply have to make sure that they have the latest version of Feedly installed, and their accounts will be migrated to Feedly Cloud over the next few days. Additionally, the new service allowed Feedly to create a stand-alone web interface (found simply at cloud.feedly.com) that works in all major browsers without plugins or extensions. The transition to Feedly Cloud has another benefit, and that is the abilit...

Google+ Rolls Out Restricted Communities for Corporate Users

Google this week rolled out a new Google+ security feature for organizations intended to help them keep certain conversations private from the larger Web. Much like Microsoft's Yammer, Google+ restricted communities will only allow access to approved employees. "Whether it's designs of your beta product or notes from your team off-site, anything you post will remain restricted to the organization," Google+ product manager Michael Cai wrote in a blog post. Community administrators can decide whether the site will remain open to everyone at the company, or kept private by invitation only. Google+ also allows for people outside of your domain — clients, agencies, business partners — to join the conversation.