Novell Home

CVE-2009-0034

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2009-0034 at MITRE

Description

parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.

NVD CVSS v2 Base Score: 6.9 (AV:L/AC:M/Au:N/C:C/I:C/A:C)

Novell/SUSE information

Novell Bugzilla entry: 468923

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 10.3
  • sudo >= 1.6.9p2-23.4

© 2012 Novell