CVE-2010-0427
CVE-2010-0427
sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gzhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=567622http://secunia.com/advisories/38762http://secunia.com/advisories/38795http://secunia.com/advisories/38803http://secunia.com/advisories/38915http://securitytracker.com/id?1023658https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10946https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7216http://sudo.ws/repos/sudo/rev/aa0b6c01c462http://wiki.rpath.com/Advisories:rPSA-2010-0075