Lucene search

K
cve[email protected]CVE-2011-0010
HistoryJan 18, 2011 - 6:03 p.m.

CVE-2011-0010

2011-01-1818:03:08
CWE-264
web.nvd.nist.gov
49
sudo
authentication bypass
cve-2011-0010
nvd

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

17.2%

check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.

Affected configurations

NVD
Node
todd_millersudoMatch1.7.0
OR
todd_millersudoMatch1.7.1
OR
todd_millersudoMatch1.7.2
OR
todd_millersudoMatch1.7.2p1
OR
todd_millersudoMatch1.7.2p2
OR
todd_millersudoMatch1.7.2p3
OR
todd_millersudoMatch1.7.2p4
OR
todd_millersudoMatch1.7.2p5
OR
todd_millersudoMatch1.7.2p6
OR
todd_millersudoMatch1.7.2p7
OR
todd_millersudoMatch1.7.3b1
OR
todd_millersudoMatch1.7.4
OR
todd_millersudoMatch1.7.4p1
OR
todd_millersudoMatch1.7.4p2
OR
todd_millersudoMatch1.7.4p3
OR
todd_millersudoMatch1.7.4p4
VendorProductVersionCPE
todd_millersudo1.7.2p6cpe:/a:todd_miller:sudo:1.7.2p6:::
todd_millersudo1.7.4p4cpe:/a:todd_miller:sudo:1.7.4p4:::
todd_millersudo1.7.0cpe:/a:todd_miller:sudo:1.7.0:::
todd_millersudo1.7.4p3cpe:/a:todd_miller:sudo:1.7.4p3:::
todd_millersudo1.7.2p2cpe:/a:todd_miller:sudo:1.7.2p2:::
todd_millersudo1.7.4cpe:/a:todd_miller:sudo:1.7.4:::
todd_millersudo1.7.2p1cpe:/a:todd_miller:sudo:1.7.2p1:::
todd_millersudo1.7.2p4cpe:/a:todd_miller:sudo:1.7.2p4:::
todd_millersudo1.7.2p5cpe:/a:todd_miller:sudo:1.7.2p5:::
todd_millersudo1.7.4p1cpe:/a:todd_miller:sudo:1.7.4p1:::
Rows per page:
1-10 of 161

References

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

17.2%