Lucene search

K
nvd[email protected]NVD:CVE-2010-0427
HistoryFeb 25, 2010 - 7:30 p.m.

CVE-2010-0427

2010-02-2519:30:00
CWE-264
web.nvd.nist.gov
8

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0

Percentile

10.1%

sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.

Affected configurations

Nvd
Node
todd_millersudoMatch1.6
OR
todd_millersudoMatch1.6.1
OR
todd_millersudoMatch1.6.2
OR
todd_millersudoMatch1.6.3
OR
todd_millersudoMatch1.6.3_p1
OR
todd_millersudoMatch1.6.3_p2
OR
todd_millersudoMatch1.6.3_p3
OR
todd_millersudoMatch1.6.3_p4
OR
todd_millersudoMatch1.6.3_p5
OR
todd_millersudoMatch1.6.3_p6
OR
todd_millersudoMatch1.6.3_p7
OR
todd_millersudoMatch1.6.4_p1
OR
todd_millersudoMatch1.6.4_p2
OR
todd_millersudoMatch1.6.5
OR
todd_millersudoMatch1.6.5_p1
OR
todd_millersudoMatch1.6.5_p2
OR
todd_millersudoMatch1.6.6
OR
todd_millersudoMatch1.6.7
OR
todd_millersudoMatch1.6.7_p5
OR
todd_millersudoMatch1.6.8
OR
todd_millersudoMatch1.6.8_p1
OR
todd_millersudoMatch1.6.8_p5
OR
todd_millersudoMatch1.6.8_p8
OR
todd_millersudoMatch1.6.8_p9
OR
todd_millersudoMatch1.6.8_p12
OR
todd_millersudoMatch1.6.9_p17
OR
todd_millersudoMatch1.6.9_p18
OR
todd_millersudoMatch1.6.9_p19

References

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0

Percentile

10.1%