sudo fails to validate users defined in sudoers Runas_list in RHEL5.5
Issue
- When specifying a Runas_List for both user and group in the sudoers file, the run as user provided with -u <user> command line argument is not validated against the user Runas_List if the group specified is valid
- According to the sudo man page, a combination of valid elements from both lists should be required.
Environment
- Red Hat Enterprise Linux 5 (RHEL5)
- Prior RHEL releases are NOT affected
- sudo package version 1.7.2p1-5.el5 released with RHEL5 Update 5 (RHEL5.5)
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.