PT-2010-1084 · Todd Miller+1 · Sudo+1
Published
2010-09-07
·
Updated
2018-10-10
·
CVE-2010-2956
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sudo versions 1.7.0 through 1.7.4p3
Description
The issue allows local users to gain privileges via a command line containing a "-u root" sequence, potentially leading to disruption of confidentiality, integrity, and availability of protected information. The exploitation can be carried out locally.
Recommendations
For Sudo versions 1.7.0 through 1.7.4p3, consider updating to a version newer than 1.7.4p3 to resolve the issue.
At the moment, there is no information about additional mitigation measures for this specific vulnerability.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Sudo