Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-0010

19
FAUCET Score

CVE-2011-0010 describes a privilege escalation vulnerability in sudo versions 1.7.x before 1.7.4p5. When a Runas group is configured, sudo fails to require a password for commands that change the group ID (gid) but not the user ID (uid), allowing local users to bypass authentication via the -g option. This vulnerability has a CVSS score of 4.4, indicating a medium severity with local access, medium attack complexity, and potential for partial confidentiality, integrity, and availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
1.7.0CPE matchmatch criteria
cpe:2.3:a:todd_miller:sudo:1.7.0:*:*:*:*:*:*:*
1.7.1CPE matchmatch criteria
cpe:2.3:a:todd_miller:sudo:1.7.1:*:*:*:*:*:*:*
1.7.2CPE matchmatch criteria
cpe:2.3:a:todd_miller:sudo:1.7.2:*:*:*:*:*:*:*
1.7.2p1CPE matchmatch criteria
cpe:2.3:a:todd_miller:sudo:1.7.2p1:*:*:*:*:*:*:*
1.7.2p2CPE matchmatch criteria
cpe:2.3:a:todd_miller:sudo:1.7.2p2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.4MEDIUM

AV:L/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
3.4
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.50%
Probability of exploitation in next 30 days
EPSS Percentile
39.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0050 is in the 76th percentile among its peer group of 1,595 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: sudo-0:1.7.2p1-13.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: sudo-0:1.7.4p5-5.el6
View patch

Vendor Advisories (1)

redhatCVE-2011-0010Low

sudo: does not ask for password on GID changes

Jan 11, 2011

References

bugs.debian.org / cgi-bin/bugreport.cgi
lists.fedoraproject.org / pipermail/package-announce/2011-January/053263.html
lists.fedoraproject.org / pipermail/package-announce/2011-January/053341.html
lists.opensuse.org / opensuse-security-announce/2011-01/msg00006.html
openwall.com / lists/oss-security/2011/01/11/3
Patch
openwall.com / lists/oss-security/2011/01/12/1
Patch
openwall.com / lists/oss-security/2011/01/12/3
bugzilla.redhat.com / show_bug.cgi
Patch
secunia.com / advisories/42886
Vendor Advisory
secunia.com / advisories/42949
secunia.com / advisories/42968
secunia.com / advisories/43068
secunia.com / advisories/43282
security.gentoo.org / glsa/glsa-201203-06.xml
exchange.xforce.ibmcloud.com / vulnerabilities/64636
slackware.com / security/viewer.php
mandriva.com / security/advisories
osvdb.org / 70400
redhat.com / support/errata/RHSA-2011-0599.html
securityfocus.com / bid/45774
sudo.ws / repos/sudo/rev/07d1b0ce530e
Patch
sudo.ws / repos/sudo/rev/fe8a94f96542
Patch
sudo.ws / sudo/alerts/runas_group_pw.html
ubuntu.com / usn/USN-1046-1
vupen.com / english/advisories/2011/0089
Vendor Advisory
vupen.com / english/advisories/2011/0182
vupen.com / english/advisories/2011/0195
vupen.com / english/advisories/2011/0199
vupen.com / english/advisories/2011/0212
vupen.com / english/advisories/2011/0362