REDHAT-BUG-2454714: High severity Sudo Sudo vulnerability
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2454714?
The severity of REDHAT-BUG-2454714 is considered critical due to the potential for privilege escalation.
How do I fix REDHAT-BUG-2454714?
To fix REDHAT-BUG-2454714, you should upgrade to a fixed version of Sudo, specifically to versions above 1.9.17p2 and below 3e474c2.
What vulnerability does REDHAT-BUG-2454714 expose?
REDHAT-BUG-2454714 exposes a vulnerability where a failure in privilege drop calls can allow unauthorized privilege escalation.
Which versions of Sudo are affected by REDHAT-BUG-2454714?
Versions of Sudo affected by REDHAT-BUG-2454714 are those from 1.9.17p2 up to, but not including, version 3e474c2.
Is there a workaround for REDHAT-BUG-2454714?
There are currently no recommended workarounds for REDHAT-BUG-2454714; updating to a secure version is advised.