Jakub Wilk and Stephane Chazelas discovered that Sudo incorrectly handled the TZ environment variable. An attacker with Sudo access could possibly use this issue to open arbitrary files, bypassing intended permissions.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.8.9p5-1ubuntu1.1", "binary_name": "sudo" }, { "binary_version": "1.8.9p5-1ubuntu1.1", "binary_name": "sudo-ldap" } ] }