← Back

CVE-2010-0427

nvd nist
Published: Feb 25, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.4
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 3.4 / Impact: 6.4
Source: NVD

Description

sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.

Affected (28)

Products: Todd Miller: Sudo
1 product
Sudo
Configuration A
28 vulnerable
Vulnerable SoftwareAffected Versions
Todd Miller
Version 1.6.1
Version 1.6.2
Version 1.6.3
Version 1.6.3_p1
Version 1.6.3_p2
Version 1.6.3_p3
Version 1.6.3_p4
Version 1.6.3_p5
Version 1.6.3_p6
Version 1.6.3_p7
Version 1.6.4_p1
Version 1.6.4_p2
Version 1.6.5
Version 1.6.5_p1
Version 1.6.5_p2
Version 1.6.6
Version 1.6.7
Version 1.6.7_p5
Version 1.6.8
Version 1.6.8_p12
Version 1.6.8_p1
Version 1.6.8_p5
Version 1.6.8_p8
Version 1.6.8_p9
Version 1.6.9_p17
Version 1.6.9_p18
Version 1.6.9_p19
Version 1.6

Related CWEs

References (42)

ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gz (unsafe URL)
Source: secalert@redhat.com
Patch
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gz (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.