Description
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-722-1 | sudo vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T04:17:10.417Z
Reserved: 2008-12-15T00:00:00.000Z
Link: CVE-2009-0034
No data.
Status : Modified
Published: 2009-01-30T19:30:00.280
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-0034
OpenCVE Enrichment
No data.
Weaknesses
Ubuntu USN