Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sudo Runas组设计错误漏洞
Vulnerability Description
Sudo是软件开发者Todd C. Miller所研发的一套用于类Unix操作系统下并允许用户通过安全的方式使用特殊的权限执行命令的程序。 Sudo 1.7.0至1.7.4p3版本设置了Runas组而不能正确地处理-u选项连同-g选项的使用。本地用户可以借助包含"-u root"序列的命令行获取特权。
CVSS Information
N/A
Vulnerability Type
N/A