Una compa�era me env�a un mensaje avis�ndome de un problema de seguridad en
sudo (ver m�s abajo).

El caso es que est� corregido en las versiones posteriores a 1.6.5p2 que no
est�n disponibles en Debian woody ni sid.

Qu� se hace en estos casos? C�mo env�o un aviso a la gente de
debian-security? Les env�o un correo a la lista? He mirado en el bts y en los
avisos de seguridad en www.debian.org y no he encontrado nada.

Gracias y un saludo

Ignacio

<MENSAJE REENVIADO>

Security Advisory - RHSA-2002:071-07
------------------------------------------------------------------------------
Description:
The sudo (superuser do) utility allows system administrators to give certain
users the ability to run commands as root with logging. 

Global InterSec LLC found an issue with Sudo 1.6.5p2 and earlier which can
be exploited to allow a local attacker to gain root privileges.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2002-0184 to this issue.

Users of Sudo are advised to upgrade to these errata packages which are
not vulnerable to this issue.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0184
http://www.globalintersec.com/adv/sudo-2002041701.txt

</MENSAJE REENVIADO>




-- 
Codigo ergo sum
-------------------------
Ignacio Garc�a Fern�ndez 
[EMAIL PROTECTED]
Instituto de Rob�tica.   
Universidad de Valencia.
Tlf. 96 398 3583


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Responder a