Lucene search

K
cve[email protected]CVE-2010-2956
HistorySep 10, 2010 - 7:00 p.m.

CVE-2010-2956

2010-09-1019:00:02
web.nvd.nist.gov
33
cve-2010-2956
sudo
runas group
local users
privilege escalation

6.2 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

8.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%

Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a “-u root” sequence.

Affected configurations

NVD
Node
todd_millersudoMatch1.7.0
OR
todd_millersudoMatch1.7.1
OR
todd_millersudoMatch1.7.2
OR
todd_millersudoMatch1.7.2p1
OR
todd_millersudoMatch1.7.2p2
OR
todd_millersudoMatch1.7.2p3
OR
todd_millersudoMatch1.7.2p4
OR
todd_millersudoMatch1.7.2p5
OR
todd_millersudoMatch1.7.2p6
OR
todd_millersudoMatch1.7.2p7
OR
todd_millersudoMatch1.7.3b1
OR
todd_millersudoMatch1.7.4
OR
todd_millersudoMatch1.7.4p1
OR
todd_millersudoMatch1.7.4p2
OR
todd_millersudoMatch1.7.4p3

References

6.2 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

8.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%