SB2010030802 - Permissions, Privileges, and Access Controls in sudo (Alpine package)
Published: March 8, 2010
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2010-0427)
The vulnerability allows a local non-authenticated attacker to read and manipulate data.
sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.
Remediation
Install update from vendor's website.