Bugtraq mailing list archives

Re: hole in sudo for MP-RAS.


From: Todd.Miller () COURTESAN COM (Todd C. Miller)
Date: Tue, 13 Jan 1998 08:41:26 -0700


Actually, that line should just be:
    if (strchr(cmnd, '/') == NULL)

This is fixed in version 1.5.4, available from:
    ftp://ftp.cs.colorado.edu/pub/sysadmin/sudo/cu-sudo.v1.5.4.tar.Z
    ftp://ftp.courtesan.com/pub/sudo/cu-sudo.v1.5.4.tar.Z (very slow link)

 - todd



Current thread: