CVE detail
CVE-2011-0008 — CVE-2011-0008
Published 2011-01-20 · Modified 2026-06-16 · Vendor todd_miller · Product sudo · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0033
EPSS probability
exploitation probability, 30d
26.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command. NOTE: this vulnerability exists because of a CVE-2009-0034 regression.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References