CVE-2010-2956
published 2010-09-10CVE-2010-2956: Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows…
PriorityP422medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.36%
28.6th percentile
Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.7.4p4-1 (bookworm) | sudo 1.7.4p4-1 (bookworm) |
| sudo_project | sudo | >= 0 < 1.7.4p4-1 | 1.7.4p4-1 |
| sudo_project | sudo | >= 0 < 1.7.4p4-1 | 1.7.4p4-1 |
| sudo_project | sudo | >= 0 < 1.7.4p4-1 | 1.7.4p4-1 |
| sudo_project | sudo | >= 0 < 1.7.4p4-1 | 1.7.4p4-1 |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| todd_miller | sudo | — | — |
| vmware | esxi | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-88qq-68fm-2rxx: Sudo 1
ghsa_unreviewed·2022-05-14
CVE-2010-2956 [MEDIUM] GHSA-88qq-68fm-2rxx: Sudo 1
Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.
OSV
CVE-2010-2956: Sudo 1
osv·2010-09-10·CVSS 6.2
CVE-2010-2956 [MEDIUM] CVE-2010-2956: Sudo 1
Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.
VMware
VMware ESX third party updates for Service Console packages glibc, sudo, and openldap
vendor_vmware·2011-01-04·CVSS 6.9
CVE-2010-0211 [MEDIUM] VMware ESX third party updates for Service Console packages glibc, sudo, and openldap
VMSA-2011-0001: VMware ESX third party updates for Service Console packages glibc, sudo, and openldap
a. Service Console update for glibc The service console packages glibc, glibc-common, and nscd are each updated to version 2.5-34.4908.vmw. The Common Vulnerabilities and Exposures project ( cve.mitre.org) has assigned the names CVE-2010-3847 and CVE-2010-3856 to the issues addressed in this update. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMware Product ============= VirtualCente Product Version ======= any Running on ======= Windows Replace with/ Apply Patch ================= not a
Red Hat
sudo: incorrect handling of RunAs specification with both user and group lists
vendor_redhat·2010-09-07·CVSS 6.2
CVE-2010-2956 [MEDIUM] sudo: incorrect handling of RunAs specification with both user and group lists
sudo: incorrect handling of RunAs specification with both user and group lists
Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.
Package: sudo (Red Hat Enterprise Linux 4) - Not affected
Package: sudo (Red Hat Enterprise Linux 6) - Not affected
Ubuntu
Sudo vulnerability
vendor_ubuntu·2010-09-07
CVE-2010-2956 Sudo vulnerability
Title: Sudo vulnerability
Summary: Under non-default configurations, a local user could run programs with
administrator privileges.
Markus Wuethrich discovered that sudo did not always verify the user when a
group was specified in the Runas_Spec. A local attacker could exploit this
to execute arbitrary code as root if sudo was configured to allow the
attacker to use a program as a group when the attacker was not a part of
that group.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2010-2956: sudo - Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly ...
vendor_debian·2010·CVSS 6.2
CVE-2010-2956 [MEDIUM] CVE-2010-2956: sudo - Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly ...
Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.
Scope: local
bookworm: resolved (fixed in 1.7.4p4-1)
bullseye: resolved (fixed in 1.7.4p4-1)
forky: resolved (fixed in 1.7.4p4-1)
sid: resolved (fixed in 1.7.4p4-1)
trixie: resolved (fixed in 1.7.4p4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-2956 sudo: incorrect handling of RunAs specification with both user and group lists [fedora-all]
bugzilla·2010-09-07·CVSS 6.2
CVE-2010-2956 [MEDIUM] CVE-2010-2956 sudo: incorrect handling of RunAs specification with both user and group lists [fedora-all]
CVE-2010-2956 sudo: incorrect handling of RunAs specification with both user and group lists [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=628628
Please no
Bugzilla
CVE-2010-2956 sudo: incorrect handling of RunAs specification with both user and group lists
bugzilla·2010-08-30·CVSS 6.2
CVE-2010-2956 [MEDIUM] CVE-2010-2956 sudo: incorrect handling of RunAs specification with both user and group lists
CVE-2010-2956 sudo: incorrect handling of RunAs specification with both user and group lists
A security flaw was found in the way Sudo performed matching
for user described by a password against the list of members,
allowed to run particular sudo command, when the group option
was specified on the command line. If a local, unprivileged
user was authorized by sudoers file to run their sudo commands
with permissions of a particular group (different to their own),
it could lead to privilege escalation (execution of that sudo
command with permissions of privileged user account (root)).
Acknowledgements:
Red Hat would like to thank Markus Wuethrich of Swiss Post - PostFinance
for reporting this issue.
Discussion:
Created attachment 441964
Proposed patch from Todd C. Miller
---
This issue
http://lists.fedoraproject.org/pipermail/package-announce/2010-September/047516.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://secunia.com/advisories/40508http://secunia.com/advisories/41316http://secunia.com/advisories/42787http://security.gentoo.org/glsa/glsa-201009-03.xmlhttp://wiki.rpath.com/Advisories:rPSA-2010-0075http://www.mandriva.com/security/advisories?name=MDVSA-2010:175http://www.redhat.com/support/errata/RHSA-2010-0675.htmlhttp://www.securityfocus.com/archive/1/514489/100/0/threadedhttp://www.securityfocus.com/archive/1/515545/100/0/threadedhttp://www.securityfocus.com/bid/43019http://www.securitytracker.com/id?1024392http://www.sudo.ws/sudo/alerts/runas_group.htmlhttp://www.ubuntu.com/usn/USN-983-1http://www.vmware.com/security/advisories/VMSA-2011-0001.htmlhttp://www.vupen.com/english/advisories/2010/2312http://www.vupen.com/english/advisories/2010/2318http://www.vupen.com/english/advisories/2010/2320http://www.vupen.com/english/advisories/2010/2358http://www.vupen.com/english/advisories/2011/0025https://bugzilla.redhat.com/show_bug.cgi?id=628628http://lists.fedoraproject.org/pipermail/package-announce/2010-September/047516.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://secunia.com/advisories/40508http://secunia.com/advisories/41316http://secunia.com/advisories/42787http://security.gentoo.org/glsa/glsa-201009-03.xmlhttp://wiki.rpath.com/Advisories:rPSA-2010-0075http://www.mandriva.com/security/advisories?name=MDVSA-2010:175http://www.redhat.com/support/errata/RHSA-2010-0675.htmlhttp://www.securityfocus.com/archive/1/514489/100/0/threadedhttp://www.securityfocus.com/archive/1/515545/100/0/threadedhttp://www.securityfocus.com/bid/43019http://www.securitytracker.com/id?1024392http://www.sudo.ws/sudo/alerts/runas_group.htmlhttp://www.ubuntu.com/usn/USN-983-1http://www.vmware.com/security/advisories/VMSA-2011-0001.htmlhttp://www.vupen.com/english/advisories/2010/2312http://www.vupen.com/english/advisories/2010/2318http://www.vupen.com/english/advisories/2010/2320http://www.vupen.com/english/advisories/2010/2358http://www.vupen.com/english/advisories/2011/0025https://bugzilla.redhat.com/show_bug.cgi?id=628628
2010-09-10
Published