CVE-2011-0010
EPSS 0.50%
描述
check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.
如何修補 CVE-2011-0010
要修補 CVE-2011-0010,請將受影響套件升級到下列已修補版本。
- Debian/sudo—升級至 1.7.4p4-6 或更新版本
CVE-2011-0010 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1.7.4p4-6