cbcvebase.
CVE-2010-2956
published 2010-09-10

CVE-2010-2956: Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows…

PriorityP422medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.36%
28.6th percentile
Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiansudo< sudo 1.7.4p4-1 (bookworm)sudo 1.7.4p4-1 (bookworm)
sudo_projectsudo>= 0 < 1.7.4p4-11.7.4p4-1
sudo_projectsudo>= 0 < 1.7.4p4-11.7.4p4-1
sudo_projectsudo>= 0 < 1.7.4p4-11.7.4p4-1
sudo_projectsudo>= 0 < 1.7.4p4-11.7.4p4-1
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
todd_millersudo
vmwareesxi
vmwarevmware_workstation

CVSS provenance

nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.