Lucene search

K
prionPRIOn knowledge basePRION:CVE-2009-0034
HistoryJan 30, 2009 - 7:30 p.m.

Authorization

2009-01-3019:30:00
PRIOn knowledge base
www.prio-n.com
6

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

40.7%

parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.

CPENameOperatorVersion
sudoeq1.6.9 p17
sudoeq1.6.9 p18
sudoeq1.6.9 p19
esxeq4.0

References