CVE-2009-0034 – sudo: incorrect handling of groups in Runas_User
https://notcve.org/view.php?id=CVE-2009-0034
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command. parse.c de sudo v1.6.9p17 hasta v1.6.9p19, no interpreta correctamente un grupo del sistema (también conocido como %group) en el fichero sudoers durante la decisión de autorización para un usuario que pertenezca a ese grupo. Esto permite a usuarios locales utilizar un fichero sudoers y obtener privilegios de root (administrador) a través de un comando sudo. • http://lists.vmware.com/pipermail/security-announce/2009/000060.html http://osvdb.org/51736 http://secunia.com/advisories/33753 http://secunia.com/advisories/33840 http://secunia.com/advisories/33885 http://secunia.com/advisories/35766 http://wiki.rpath.com/Advisories:rPSA-2009-0021 http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327 http://www.mandriva.com/security/advisories?name=MDVSA-2009:033 http://www.redhat.com/support/errata/RHSA-2009-0267.html http://www.secu • CWE-863: Incorrect Authorization •