4.4

CVE-2011-0010

check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.

Data is provided by the National Vulnerability Database (NVD)
Todd MillerSudo Version1.7.0
Todd MillerSudo Version1.7.1
Todd MillerSudo Version1.7.2
Todd MillerSudo Version1.7.2p1
Todd MillerSudo Version1.7.2p2
Todd MillerSudo Version1.7.2p3
Todd MillerSudo Version1.7.2p4
Todd MillerSudo Version1.7.2p5
Todd MillerSudo Version1.7.2p6
Todd MillerSudo Version1.7.2p7
Todd MillerSudo Version1.7.3b1
Todd MillerSudo Version1.7.4
Todd MillerSudo Version1.7.4p1
Todd MillerSudo Version1.7.4p2
Todd MillerSudo Version1.7.4p3
Todd MillerSudo Version1.7.4p4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.304
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P