Back to search
CVE-2011-0010
Published: Jan 18, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ADV-2011-0362
vdb-entry
x_refsource_VUPEN
http://www.sudo.ws/sudo/alerts/runas_group_pw.html
x_refsource_CONFIRM
43068
third-party-advisory
x_refsource_SECUNIA
GLSA-201203-06
vendor-advisory
x_refsource_GENTOO
SSA:2011-041-05
vendor-advisory
x_refsource_SLACKWARE
MDVSA-2011:018
vendor-advisory
x_refsource_MANDRIVA
http://www.sudo.ws/repos/sudo/rev/07d1b0ce530e
x_refsource_MISC
ADV-2011-0089
vdb-entry
x_refsource_VUPEN
ADV-2011-0212
vdb-entry
x_refsource_VUPEN
42949
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20110111 CVE request: sudo does not ask for password on GID changes
mailing-list
x_refsource_MLIST
ADV-2011-0182
vdb-entry
x_refsource_VUPEN
FEDORA-2011-0470
vendor-advisory
x_refsource_FEDORA
ADV-2011-0199
vdb-entry
x_refsource_VUPEN
USN-1046-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2011:0599
vendor-advisory
x_refsource_REDHAT
[oss-security] 20110112 Re: CVE request: sudo does not ask for password on GID changes
mailing-list
x_refsource_MLIST
70400
vdb-entry
x_refsource_OSVDB
42886
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2011:002
vendor-advisory
x_refsource_SUSE
sudo-groupid-privilege-escalation(64636)
vdb-entry
x_refsource_XF
45774
vdb-entry
x_refsource_BID
[oss-security] 20110112 Re: CVE request: sudo does not ask for password on GID changes
mailing-list
x_refsource_MLIST
43282
third-party-advisory
x_refsource_SECUNIA
FEDORA-2011-0455
vendor-advisory
x_refsource_FEDORA
http://www.sudo.ws/repos/sudo/rev/fe8a94f96542
x_refsource_CONFIRM
ADV-2011-0195
vdb-entry
x_refsource_VUPEN
https://bugzilla.redhat.com/show_bug.cgi?id=668879
x_refsource_CONFIRM
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=609641
x_refsource_CONFIRM
42968
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now