CVE-2009-0034

Publication date 30 January 2009

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

7.8 · High

Score breakdown

parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.

Status

Package Ubuntu Release Status
sudo 8.10 intrepid
Fixed 1.6.9p17-1ubuntu2.1
8.04 LTS hardy
Fixed 1.6.9p10-1ubuntu3.4
7.10 gutsy
Not affected
6.06 LTS dapper
Not affected

Severity score breakdown

Parameter Value
Base score 7.8 · High
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Related Ubuntu Security Notices (USN)

    • USN-722-1
    • sudo vulnerability
    • 17 February 2009

Other references