PT-2011-1177 · Todd Miller+1 · Sudo+1
Alexander Kurtz
·
Published
2011-01-18
·
Updated
2024-06-15
·
CVE-2011-0010
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
sudo versions prior to 1.8.3 p2
sudo versions 1.7.x before 1.7.4p5
Description
The issue affects the sudo package in Gentoo Linux, potentially compromising confidentiality, integrity, and availability of protected information. Exploitation can be done locally. Specifically, in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, the
check.c file does not require a password for command execution involving a gid change but no uid change, allowing local users to bypass intended authentication via the -g option to a sudo command.Recommendations
For versions prior to 1.8.3 p2, update to version 1.8.3 p2 or later.
For versions 1.7.x before 1.7.4p5, update to version 1.7.4p5 or later.
As a temporary workaround, consider restricting the use of the
-g option in sudo commands until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Sudo