CVE-2011-0010

NameCVE-2011-0010
Descriptioncheck.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs609641

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
sudo (PTS)stretch1.8.19p1-2.1+deb9u2fixed
stretch (security)1.8.19p1-2.1+deb9u3fixed
buster, buster (security)1.8.27-1+deb10u3fixed
bullseye, sid1.9.5p2-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sudosourcelenny(not affected)
sudosourcesqueeze1.7.4p4-2.squeeze.1
sudosource(unstable)1.7.4p4-6609641

Notes

[lenny] - sudo <not-affected> (Only affects 1.7.x)
http://www.sudo.ws/sudo/alerts/runas_group_pw.html

Search for package or bug name: Reporting problems