Description
Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2010-2960 | Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence. |
Ubuntu USN |
USN-983-1 | Sudo vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T02:55:46.374Z
Reserved: 2010-08-04T00:00:00.000Z
Link: CVE-2010-2956
No data.
Status : Modified
Published: 2010-09-10T19:00:02.830
Modified: 2026-04-29T01:13:23.040
Link: CVE-2010-2956
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN