[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-0008Date: (C)2011-01-20   (M)2024-01-19


A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command. NOTE: this vulnerability exists because of a CVE-2009-0034 regression.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.9
Exploit Score: 3.4
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECUNIA-42968
ADV-2011-0195
ADV-2011-0199
FEDORA-2011-0455
FEDORA-2011-0470
MDVSA-2011:018
https://bugzilla.redhat.com/show_bug.cgi?id=668843
sudo-parse-privilege-escalation(64965)

CPE    36
cpe:/a:todd_miller:sudo:1.6
cpe:/a:todd_miller:sudo:1.7.3b1
cpe:/a:todd_miller:sudo:1.6.4p2
cpe:/a:todd_miller:sudo:1.7.2p4
...
OVAL    3
oval:org.secpod.oval:def:301106
oval:org.secpod.oval:def:101163
oval:org.secpod.oval:def:101165

© SecPod Technologies