Mac OS X 10.6 Snow Leopard
The sudo
utility for executing a command on behalf of another user (most prominent: root) is configured such that the sudo timestamp is valid for all sessions of a user, not just the current one. In particular it can outlive the current session. This can be regarded as a security flaw. To restrict the privilege change to the current session, the tty_tickets
sudoers option needs to be enabled by running visudo
, adding the line