PT-2011-1177 · Todd Miller+1 · Sudo+1

Alexander Kurtz

·

Published

2011-01-18

·

Updated

2024-06-15

·

CVE-2011-0010

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions sudo versions prior to 1.8.3 p2 sudo versions 1.7.x before 1.7.4p5
Description The issue affects the sudo package in Gentoo Linux, potentially compromising confidentiality, integrity, and availability of protected information. Exploitation can be done locally. Specifically, in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, the check.c file does not require a password for command execution involving a gid change but no uid change, allowing local users to bypass intended authentication via the -g option to a sudo command.
Recommendations For versions prior to 1.8.3 p2, update to version 1.8.3 p2 or later. For versions 1.7.x before 1.7.4p5, update to version 1.7.4p5 or later. As a temporary workaround, consider restricting the use of the -g option in sudo commands until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09434
CVE-2011-0010
OPENSUSE-SU-2024:10551-1
RHSA-2011:0599
RHSA-2011_0599
RHSA-2012:0309
RHSA-2012_0309

Affected Products

Red Hat
Sudo