Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.gratisoft.us/pipermail/sudo-announce/2009-February/000085.html http://www.vuxml.org/freebsd/13d6d997-f455-11dd-8516-001b77d09812.html
Insight
The following package is affected: sudo
CVE-2009-0034
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
Severity
Classification
-
CVE CVE-2009-0034 -
CVSS Base Score: 6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities