CVE-2009-0034
published 2009-01-30CVE-2009-0034: parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user…
PriorityP433high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
33.0th percentile
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
Affected
124 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.6.9p17-2 (bookworm) | sudo 1.6.9p17-2 (bookworm) |
| debian | sudo | — | — |
| gratisoft | sudo | — | — |
| sudo_project | sudo | >= 0 < 1.6.9p17-2 | 1.6.9p17-2 |
| sudo_project | sudo | >= 0 < 1.6.9p17-2 | 1.6.9p17-2 |
| sudo_project | sudo | >= 0 < 1.6.9p17-2 | 1.6.9p17-2 |
| sudo_project | sudo | >= 0 < 1.6.9p17-2 | 1.6.9p17-2 |
| todd_miller | sudo | <= 1.7.4p5 | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8MEDIUM
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
sudo in Fedora vulnerable to CVE-2009-0034 again due to improper patch rediff
vendor_redhat·2011-01-14·CVSS 7.8
CVE-2011-0008 [HIGH] sudo in Fedora vulnerable to CVE-2009-0034 again due to improper patch rediff
sudo in Fedora vulnerable to CVE-2009-0034 again due to improper patch rediff
A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command. NOTE: this vulnerability exists because of a CVE-2009-0034 regression.
Statement: Not vulnerable. This issue did not affect the versions of sudo as shipped with Red Hat Enterprise Linux 4, 5, or 6.
Debian
CVE-2011-0008: sudo - A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 do...
vendor_debian·2011·CVSS 7.8
CVE-2011-0008 [HIGH] CVE-2011-0008: sudo - A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 do...
A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command. NOTE: this vulnerability exists because of a CVE-2009-0034 regression.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
VMware
ESX Service Console updates for udev, sudo, and curl
vendor_vmware·2009-07-10·CVSS 7.2
CVE-2009-0034 [HIGH] ESX Service Console updates for udev, sudo, and curl
VMSA-2009-0009: ESX Service Console updates for udev, sudo, and curl
a. Service Console package udev A vulnerability in the udev program did not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2009-1185 to this issue. Please see http://kb.vmware.com/kb/1011786 for details. The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Product VirtualCenter Product Version any Running on Windows Replace with/ Apply Patch not affected VMware Product hosted * Product Version any Runn
Ubuntu
sudo vulnerability
vendor_ubuntu·2009-02-17
CVE-2009-0034 sudo vulnerability
Title: sudo vulnerability
Summary: sudo vulnerability
Harald Koenig discovered that sudo did not correctly handle certain
privilege changes when handling groups. If a local attacker belonged
to a group included in a "RunAs" list in the /etc/sudoers file, that
user could gain root privileges. This was not an issue for the default
sudoers file shipped with Ubuntu.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
sudo: incorrect handling of groups in Runas_User
vendor_redhat·2009-01-23·CVSS 7.8
CVE-2009-0034 [HIGH] sudo: incorrect handling of groups in Runas_User
sudo: incorrect handling of groups in Runas_User
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
Debian
CVE-2009-0034: sudo - parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system g...
vendor_debian·2009·CVSS 7.8
CVE-2009-0034 [HIGH] CVE-2009-0034: sudo - parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system g...
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
Scope: local
bookworm: resolved (fixed in 1.6.9p17-2)
bullseye: resolved (fixed in 1.6.9p17-2)
forky: resolved (fixed in 1.6.9p17-2)
sid: resolved (fixed in 1.6.9p17-2)
trixie: resolved (fixed in 1.6.9p17-2)
GHSA
GHSA-p276-77q6-c7jq: A certain Fedora patch for parse
ghsa_unreviewed·2022-05-03·CVSS 7.8
CVE-2011-0008 [HIGH] GHSA-p276-77q6-c7jq: A certain Fedora patch for parse
A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command. NOTE: this vulnerability exists because of a CVE-2009-0034 regression.
GHSA
GHSA-4x95-346p-g442: parse
ghsa_unreviewed·2022-05-02
CVE-2009-0034 [MEDIUM] CWE-863 GHSA-4x95-346p-g442: parse
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
OSV
CVE-2009-0034: parse
osv·2009-01-30·CVSS 7.8
CVE-2009-0034 [HIGH] CVE-2009-0034: parse
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0008 sudo in Fedora vulnerable to CVE-2009-0034 again due to improper patch rediff
bugzilla·2011-01-11·CVSS 7.8
CVE-2011-0008 [HIGH] CVE-2011-0008 sudo in Fedora vulnerable to CVE-2009-0034 again due to improper patch rediff
CVE-2011-0008 sudo in Fedora vulnerable to CVE-2009-0034 again due to improper patch rediff
Due to upstream changes in how sudo 1.7.3 handles group membership checks, the patch used to correct bug #235915 (sudo can't always correctly determine group memberships) was incorrectly rediffed, making sudo in Fedora once again vulnerable to CVE-2009-0034 (incorrect handling of groups in Runas_User).
Statement:
Not vulnerable. This issue did not affect the versions of sudo as shipped with Red Hat Enterprise Linux 4, 5, or 6.
Discussion:
Created attachment 472949
corrected getgrouplist patch
Bugzilla
CVE-2009-0034 sudo: incorrect handling of groups in Runas_User
bugzilla·2009-01-27·CVSS 7.8
CVE-2009-0034 [HIGH] CVE-2009-0034 sudo: incorrect handling of groups in Runas_User
CVE-2009-0034 sudo: incorrect handling of groups in Runas_User
It was discovered that sudo's sudoers file parses does not correctly handle group specification in Runas_User. If group was specified in the list (using syntax %group, to allow some user to run commands as any member of the group) and the user was already member of the group, sudo actually allowed the user to run commands as arbitrary system user.
SuSE and upstream bug report:
https://bugzilla.novell.com/show_bug.cgi?id=468923
http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327
This issue was confirmed on multiple 1.6.9 sudo versions. Latest upstream 1.7.0 was reported not to be affected, 1.6.8p12 previously shipped with Red Hat Enterprise Linux 5 was not affected as well. Problem was confirmed on 1.6.9p17 in RHEL5 and Fedo
CWE
Incorrect Authorization
mitre_cwe
CWE-863 Incorrect Authorization
CWE-863: Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Background: An access control list (ACL) represents who/what has permissions to a given object. Different operating systems implement (ACLs) in different ways. In UNIX, there are three types of permissions: read, write, and execute. Users are divided into three classes for file access: owner, group owner, and all other users where each class has a separate set of rights. In Windows NT, there are four basic types of permissions for files: "No access", "Read access", "Change access", and "Full control". Windows NT extends the concept of three types of users in UNIX to include a list of users and groups al
CWE
Improper Authorization
mitre_cwe
CWE-285 Improper Authorization
CWE-285: Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Background: An access control list (ACL) represents who/what has permissions to a given object. Different operating systems implement (ACLs) in different ways. In UNIX, there are three types of permissions: read, write, and execute. Users are divided into three classes for file access: owner, group owner, and all other users where each class has a separate set of rights. In Windows NT, there are four basic types of permissions for files: "No access", "Read access", "Change access", and "Full control". Windows NT extends the concept of three types of users in UNIX to include a list of users and groups along with their
CWE
Missing Authorization
mitre_cwe
CWE-862 Missing Authorization
CWE-862: Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Background: An access control list (ACL) represents who/what has permissions to a given object. Different operating systems implement (ACLs) in different ways. In UNIX, there are three types of permissions: read, write, and execute. Users are divided into three classes for file access: owner, group owner, and all other users where each class has a separate set of rights. In Windows NT, there are four basic types of permissions for files: "No access", "Read access", "Change access", and "Full control". Windows NT extends the concept of three types of users in UNIX to include a list of users and groups along with their associated permissions.
http://lists.vmware.com/pipermail/security-announce/2009/000060.htmlhttp://osvdb.org/51736http://secunia.com/advisories/33753http://secunia.com/advisories/33840http://secunia.com/advisories/33885http://secunia.com/advisories/35766http://wiki.rpath.com/Advisories:rPSA-2009-0021http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327http://www.mandriva.com/security/advisories?name=MDVSA-2009:033http://www.redhat.com/support/errata/RHSA-2009-0267.htmlhttp://www.securityfocus.com/archive/1/500546/100/0/threadedhttp://www.securityfocus.com/archive/1/504849/100/0/threadedhttp://www.securityfocus.com/bid/33517http://www.securitytracker.com/id?1021688http://www.sudo.ws/cgi-bin/cvsweb/sudo/parse.c.diff?r1=1.160.2.21&r2=1.160.2.22&f=hhttp://www.vmware.com/security/advisories/VMSA-2009-0009.htmlhttp://www.vupen.com/english/advisories/2009/1865https://bugzilla.novell.com/show_bug.cgi?id=468923https://issues.rpath.com/browse/RPL-2954https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10856https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6462http://lists.vmware.com/pipermail/security-announce/2009/000060.htmlhttp://osvdb.org/51736http://secunia.com/advisories/33753http://secunia.com/advisories/33840http://secunia.com/advisories/33885http://secunia.com/advisories/35766http://wiki.rpath.com/Advisories:rPSA-2009-0021http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327http://www.mandriva.com/security/advisories?name=MDVSA-2009:033http://www.redhat.com/support/errata/RHSA-2009-0267.htmlhttp://www.securityfocus.com/archive/1/500546/100/0/threadedhttp://www.securityfocus.com/archive/1/504849/100/0/threadedhttp://www.securityfocus.com/bid/33517http://www.securitytracker.com/id?1021688http://www.sudo.ws/cgi-bin/cvsweb/sudo/parse.c.diff?r1=1.160.2.21&r2=1.160.2.22&f=hhttp://www.vmware.com/security/advisories/VMSA-2009-0009.htmlhttp://www.vupen.com/english/advisories/2009/1865https://bugzilla.novell.com/show_bug.cgi?id=468923https://issues.rpath.com/browse/RPL-2954https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10856https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6462
2009-01-30
Published