Rapid7 Vulnerability & Exploit Database

RHSA-2011:0599: sudo security and bug fix update

Free InsightVM Trial No credit card necessary
Watch Demo See how it all works
Back to Search

RHSA-2011:0599: sudo security and bug fix update

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
01/18/2011
Created
07/25/2018
Added
06/02/2011
Modified
07/04/2017

Description

The sudo (superuser do) utility allows system administrators to givecertain users the ability to run commands as root.A flaw was found in the sudo password checking logic. In configurationswhere the sudoers settings allowed a user to run a command using sudo withonly the group ID changed, sudo failed to prompt for the user's passwordbefore running the specified command with the elevated group privileges.(CVE-2011-0010)This update also fixes the following bugs:All users of sudo are advised to upgrade to this updated package, whichresolves these issues.

Solution(s)

  • redhat-upgrade-sudo
  • redhat-upgrade-sudo-debuginfo

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;