Rich Mirch discovered that sudo, a program designed to provide limited super user privileges to specific users, does not correctly handle the host (-h or --host) option. Due to a bug the host option was not restricted to listing privileges only and could be used when running a command via sudo or editing a file with sudoedit. Depending on the rules present in the sudoers file the flaw might allow a local privilege escalation attack.
https://security-tracker.debian.org/tracker/DSA-5954-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-5954-1
Continue reading...

