Sploitus

CVE-2010-0427

1 known exploit for CVE-2010-0427

sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.

Affected products
Alt Linux, Red Hat, Sudo
Todd Miller Sudo
= 1.6, 1.6.1, 1.6.2, 1.6.3, 1.6.3_p1, 1.6.3_p2, 1.6.3_p3, 1.6.3_p4, 1.6.3_p5, 1.6.3_p6, 1.6.3_p7, 1.6.4_p1, 1.6.4_p2, 1.6.5, 1.6.5_p1, 1.6.5_p2, 1.6.6, 1.6.7, 1.6.7_p5, 1.6.8, 1.6.8_p1, 1.6.8_p5, 1.6.8_p8, 1.6.8_p9, 1.6.8_p12, 1.6.9_p17, 1.6.9_p18, 1.6.9_p19
Fix
Available
CVSS 2.0
4.4 MEDIUM
EPSS
0.5% (38th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2010-02-25
CVE-2010-0427 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2010-0427

Proof-of-concept code and exploit modules indexed by Sploitus