CVE-2011-0008: Medium severity sudo vulnerability
A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command. NOTE: this vulnerability exists because of a CVE-2009-0034 regression.
Other sources
Due to upstream changes in how sudo 1.7.3 handles group membership checks, the patch used to correct bug #235915 (sudo can't always correctly determine group memberships) was incorrectly rediffed, making sudo in Fedora once again vulnerable to CVE-2009-0034 (incorrect handling of groups in RunasUser).
Statement:
Not vulnerable. This issue did not affect the versions of sudo as shipped with Red Hat Enterprise Linux 4, 5, or 6.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0008?
CVE-2011-0008 is considered a critical vulnerability that allows local users to gain unauthorized root access.
How do I fix CVE-2011-0008?
To mitigate CVE-2011-0008, it is recommended to upgrade to a patched version of sudo such as 1.7.4p5 or later.
What systems are affected by CVE-2011-0008?
CVE-2011-0008 affects various versions of the sudo utility, particularly those prior to 1.7.4p5 on Fedora 14.
Can CVE-2011-0008 be exploited remotely?
No, CVE-2011-0008 requires local user access to exploit the vulnerability.
What implications does CVE-2011-0008 have for system security?
CVE-2011-0008 poses a significant risk as it allows local users to elevate their privileges, leading to potential system compromises.