PT-2010-1079 · Todd Miller+2 · Sudo+2

Jan Lieskovsky

·

Publicado

2010-02-25

·

Atualizado

2018-10-10

·

CVE-2010-0427

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions sudo versions 1.6.x through 1.6.9p20 sudo versions prior to 1.7.2p4
Description The issue allows local users to gain privileges via a sudo command when the runas default option is used, due to improper setting of group memberships. Multiple vulnerabilities in the sudo package can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally.
Recommendations For sudo versions 1.6.x through 1.6.9p20, update to version 1.6.9p21 or later. For sudo versions prior to 1.7.2p4, update to version 1.7.2p4 or later. As a temporary workaround, consider restricting the use of the sudo command when the runas default option is used, until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1056
BDU:2015-08594
BDU:2015-09414
CVE-2010-0427
DSA-2006-1
RHSA-2010:0122
RHSA-2010_0122

Produtos afetados

Alt Linux
Red Hat
Sudo