CVE detail
CVE-2011-0010 — CVE-2011-0010
Published 2011-01-18 · Modified 2026-06-16 · Vendor todd_miller · Product sudo · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0050
EPSS probability
exploitation probability, 30d
40.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References