Todd Miller Sudo 'Runas_Alias' Supplementary Group Local Privilege Escalation Vulnerability

Bugtraq ID: 33517
Class: Design Error
CVE: CVE-2009-0034
CVE-2011-0008
Remote: No
Local: Yes
Published: Jan 29 2009 12:00AM
Updated: Jan 21 2011 09:41PM
Credit: Harald Koenig
Vulnerable: VMWare ESX Server 4.0
Ubuntu Ubuntu Linux 8.10 sparc
Ubuntu Ubuntu Linux 8.10 powerpc
Ubuntu Ubuntu Linux 8.10 lpia
Ubuntu Ubuntu Linux 8.10 i386
Ubuntu Ubuntu Linux 8.10 amd64
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu Ubuntu Linux 8.04 LTS i386
Ubuntu Ubuntu Linux 8.04 LTS amd64
Todd Miller Sudo 1.6.9 p19
Todd Miller Sudo 1.6.9 p18
Todd Miller Sudo 1.6.9 p17
SuSE openSUSE 10.3
S.u.S.E. openSUSE 11.1
S.u.S.E. openSUSE 11.0
rPath rPath Linux 2
RedHat Enterprise Linux 5 server
Red Hat Fedora 14
Red Hat Fedora 13
Red Hat Enterprise Linux Desktop 5 client
Pardus Linux 2008 0
OpenBSD OpenBSD 4.4
OpenBSD OpenBSD 4.3
MandrakeSoft Linux Mandrake 2010.1 x86_64
MandrakeSoft Linux Mandrake 2010.1
MandrakeSoft Linux Mandrake 2010.0 x86_64
MandrakeSoft Linux Mandrake 2010.0
MandrakeSoft Linux Mandrake 2009.0 x86_64
MandrakeSoft Linux Mandrake 2009.0
MandrakeSoft Linux Mandrake 2008.1 x86_64
MandrakeSoft Linux Mandrake 2008.1
MandrakeSoft Linux Mandrake 2008.0 x86_64
MandrakeSoft Linux Mandrake 2008.0
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Gentoo Linux
Not Vulnerable: Todd Miller Sudo 1.7
Todd Miller Sudo cvs


 

Privacy Statement
Copyright 2010, SecurityFocus