REDHAT-BUG-567622: High severity centos sudo vulnerability
Sudo failed to properly reset group permissions, when "runasdefault" option was used. If a local, unprivileged user was authorized by sudoers file to perform their sudo commands under default user account, it could lead to privilege escalation.
Upstream bug report: http://www.gratisoft.us/bugzilla/showbug.cgi?id=349
Upstream patch: http://www.gratisoft.us/bugzilla/attachment.cgi?id=255
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-567622?
The severity of REDHAT-BUG-567622 is considered critical due to the potential for privilege escalation.
How can I mitigate REDHAT-BUG-567622?
To mitigate REDHAT-BUG-567622, ensure that unprivileged users do not have authorization to run commands with Sudo using the 'runas_default' option.
What versions of Sudo are affected by REDHAT-BUG-567622?
REDHAT-BUG-567622 affects specific versions of Sudo where the 'runas_default' option is misconfigured.
Is there a patch available for REDHAT-BUG-567622?
Yes, a patch is available for REDHAT-BUG-567622 and should be applied to affected systems promptly.
Who is impacted by REDHAT-BUG-567622?
Any system utilizing a vulnerable version of Sudo with improperly configured sudoers files is impacted by REDHAT-BUG-567622.