PT-2010-1079 · Todd Miller+2 · Sudo+2
Jan Lieskovsky
·
Publicado
2010-02-25
·
Atualizado
2018-10-10
·
CVE-2010-0427
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
sudo versions 1.6.x through 1.6.9p20
sudo versions prior to 1.7.2p4
Description
The issue allows local users to gain privileges via a sudo command when the runas default option is used, due to improper setting of group memberships. Multiple vulnerabilities in the sudo package can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally.
Recommendations
For sudo versions 1.6.x through 1.6.9p20, update to version 1.6.9p21 or later.
For sudo versions prior to 1.7.2p4, update to version 1.7.2p4 or later.
As a temporary workaround, consider restricting the use of the sudo command when the runas default option is used, until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Red Hat
Sudo