Back

HIGH

sudo: incorrect handling of groups in Runas_User

Published Jan 30, 2009

Description

parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.

Affected products

Remediation

No remediation recorded yet.

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 30, 2009
Updated Aug 7, 2024
Reserved Dec 15, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jan 23, 2009