Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-0010

Опубликовано: 11 янв. 2011
Источник: redhat
CVSS2: 1.2
EPSS Низкий

Описание

check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4sudoNot affected
Red Hat Enterprise Linux 5sudoFixedRHSA-2012:030921.02.2012
Red Hat Enterprise Linux 6sudoFixedRHSA-2011:059919.05.2011

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=668879sudo: does not ask for password on GID changes

EPSS

Процентиль: 33%
0.00124
Низкий

1.2 Low

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.

nvd
больше 14 лет назад

check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.

debian
больше 14 лет назад

check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured ...

github
около 3 лет назад

check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.

oracle-oval
больше 13 лет назад

ELSA-2012-0309: sudo security and bug fix update (LOW)

EPSS

Процентиль: 33%
0.00124
Низкий

1.2 Low

CVSS2