PT-2010-1079 · Todd Miller+2 · Sudo+2
Jan Lieskovsky
·
Published
2010-02-25
·
Updated
2018-10-10
·
CVE-2010-0427
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
sudo versions 1.6.x through 1.6.9p20
sudo versions prior to 1.7.2p4
Description
The issue allows local users to gain privileges via a sudo command when the runas default option is used, due to improper setting of group memberships. Multiple vulnerabilities in the sudo package can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally.
Recommendations
For sudo versions 1.6.x through 1.6.9p20, update to version 1.6.9p21 or later.
For sudo versions prior to 1.7.2p4, update to version 1.7.2p4 or later.
As a temporary workaround, consider restricting the use of the sudo command when the runas default option is used, until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Red Hat
Sudo