CVE Database
/

CVE-2010-2956

Back to search

CVE-2010-2956

Published: Sep 10, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2010-2312
vdb-entry
x_refsource_VUPEN
ADV-2010-2318
vdb-entry
x_refsource_VUPEN
MDVSA-2010:175
vendor-advisory
x_refsource_MANDRIVA
ADV-2010-2320
vdb-entry
x_refsource_VUPEN
20101027 rPSA-2010-0075-1 sudo
mailing-list
x_refsource_BUGTRAQ
ADV-2010-2358
vdb-entry
x_refsource_VUPEN
FEDORA-2010-14355
vendor-advisory
x_refsource_FEDORA
GLSA-201009-03
vendor-advisory
x_refsource_GENTOO
SUSE-SR:2010:017
vendor-advisory
x_refsource_SUSE
43019
vdb-entry
x_refsource_BID
RHSA-2010:0675
vendor-advisory
x_refsource_REDHAT
40508
third-party-advisory
x_refsource_SECUNIA
1024392
vdb-entry
x_refsource_SECTRACK
42787
third-party-advisory
x_refsource_SECUNIA
ADV-2011-0025
vdb-entry
x_refsource_VUPEN
USN-983-1
vendor-advisory
x_refsource_UBUNTU
41316
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now