Lucene search

K
redhatRedHatRHSA-2009:0267
HistoryFeb 05, 2009 - 12:00 a.m.

(RHSA-2009:0267) Moderate: sudo security update

2009-02-0500:00:00
access.redhat.com
12

0.001 Low

EPSS

Percentile

40.7%

The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root with logging.

A flaw was discovered in a way sudo handled group specifications in β€œrun
as” lists in the sudoers configuration file. If sudo configuration allowed
a user to run commands as any user of some group and the user was also a
member of that group, sudo incorrectly allowed them to run defined commands
with the privileges of any system user. This gave the user unintended
privileges. (CVE-2009-0034)

Users of sudo should update to this updated package, which contains a
backported patch to resolve this issue.