CVE-2011-0008 - CVE House
Back to Database
Status published Medium CVE-2011-0008

A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14...

Vulnerability Description

A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command. NOTE: this vulnerability exists because of a CVE-2009-0034 regression.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-0008

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

todd miller

View all reports →

Affected Software

sudo
Vulnerable Versions:
0, 1.3.1, 1.5, 1.5.2, 1.5.3, 1.5.6, 1.5.7, 1.5.8, 1.5.9, 1.6, 1.6.1, 1.6.2, 1.6.2p1, 1.6.2p2, 1.6.2p3, 1.6.3, 1.6.3_p1, 1.6.3_p2, 1.6.3_p3, 1.6.3_p4, 1.6.3_p5, 1.6.3_p6, 1.6.3_p7, 1.6.3p1, 1.6.3p2, 1.6.3p3, 1.6.3p4, 1.6.3p5, 1.6.3p6, 1.6.3p7, 1.6.4, 1.6.4_p1, 1.6.4_p2, 1.6.4p1, 1.6.4p2, 1.6.5, 1.6.5_p1, 1.6.5_p2, 1.6.5p1, 1.6.5p2, 1.6.6, 1.6.7, 1.6.7_p5, 1.6.7p1, 1.6.7p2, 1.6.7p3, 1.6.7p4, 1.6.7p5, 1.6.8, 1.6.8_p1, 1.6.8_p2, 1.6.8_p5, 1.6.8_p7, 1.6.8_p8, 1.6.8_p9, 1.6.8_p12, 1.6.8p1, 1.6.8p2, 1.6.8p3, 1.6.8p4, 1.6.8p5, 1.6.8p6, 1.6.8p7, 1.6.8p8, 1.6.8p9, 1.6.8p10, 1.6.8p11, 1.6.8p12, 1.6.9, 1.6.9_p17, 1.6.9_p18, 1.6.9_p19, 1.6.9_p20, 1.6.9_p21, 1.6.9_p22, 1.6.9p1, 1.6.9p2, 1.6.9p3, 1.6.9p4, 1.6.9p5, 1.6.9p6, 1.6.9p7, 1.6.9p8, 1.6.9p9, 1.6.9p10, 1.6.9p11, 1.6.9p12, 1.6.9p13, 1.6.9p14, 1.6.9p15, 1.6.9p16, 1.6.9p17, 1.6.9p18, 1.6.9p19, 1.6.9p20, 1.6.9p21, 1.6.9p22, 1.6.9p23, 1.7.0, 1.7.1, 1.7.2, 1.7.2p1, 1.7.2p2, 1.7.2p3, 1.7.2p4, 1.7.2p5, 1.7.2p6, 1.7.2p7, 1.7.3b1, 1.7.4, 1.7.4p1, 1.7.4p2, 1.7.4p3, 1.7.4p4

Timeline

Official Publish: January 20th, 2011
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.