sudo contains a flaw that may allow an attacker to execute arbitrary files with elevated privileges. The issue is triggered when sudo is configured to use a secure path and the PATH variable is defined twice.
Upgrade to version 1.6.9p23 and sudo 1.7.2p7 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.