PT-2010-1079 · Todd Miller+2 · Sudo+2

Jan Lieskovsky

·

Published

2010-02-25

·

Updated

2018-10-10

·

CVE-2010-0427

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions sudo versions 1.6.x through 1.6.9p20 sudo versions prior to 1.7.2p4
Description The issue allows local users to gain privileges via a sudo command when the runas default option is used, due to improper setting of group memberships. Multiple vulnerabilities in the sudo package can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally.
Recommendations For sudo versions 1.6.x through 1.6.9p20, update to version 1.6.9p21 or later. For sudo versions prior to 1.7.2p4, update to version 1.7.2p4 or later. As a temporary workaround, consider restricting the use of the sudo command when the runas default option is used, until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1056
BDU:2015-08594
BDU:2015-09414
CVE-2010-0427
DSA-2006-1
RHSA-2010:0122
RHSA-2010_0122

Affected Products

Alt Linux
Red Hat
Sudo