CVE-2010-2956

Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.

Published: 2010-09-10 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2010-2956 is rated Low Risk (30.3/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2010-2956

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-17 0.04% 0.06% +0.02%
2 2023-03-07 1.55% 0.04% -1.50%
3 2022-02-04 1.55%

Full EPSS history (3 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2010-2956

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.2 2.0 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:H)
Exploitation requires uncommon or highly specific conditions.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
1.9 10.0 [email protected]

Weakness enumeration for CVE-2010-2956

OS Trackers for CVE-2010-2956

vendor priority summary link
debian not yet assigned CVE-2010-2956 not yet assigned priority: Debian including 1 source packages (sudo), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2010-2956
gentoo high CVE-2010-2956: 1 GLSA(s) (201009-03), 1 atom(s) (app-admin/sudo); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2010-2956
redhat high https://access.redhat.com/security/cve/CVE-2010-2956
ubuntu medium CVE-2010-2956 medium priority: Ubuntu including 1 source packages (sudo), 6 status rows across 6 suites (dapper, hardy, jaunty, karmic, lucid, upstream): not-affected 3, released 2, pending 1. https://ubuntu.com/security/CVE-2010-2956

Affected software / configurations for CVE-2010-2956

Vendor Product Version Raw CPE
todd_miller sudo 1.7.0 cpe:2.3:a:todd_miller:sudo:1.7.0:*:*:*:*:*:*:*
todd_miller sudo 1.7.1 cpe:2.3:a:todd_miller:sudo:1.7.1:*:*:*:*:*:*:*
todd_miller sudo 1.7.2 cpe:2.3:a:todd_miller:sudo:1.7.2:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p1 cpe:2.3:a:todd_miller:sudo:1.7.2p1:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p2 cpe:2.3:a:todd_miller:sudo:1.7.2p2:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p3 cpe:2.3:a:todd_miller:sudo:1.7.2p3:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p4 cpe:2.3:a:todd_miller:sudo:1.7.2p4:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p5 cpe:2.3:a:todd_miller:sudo:1.7.2p5:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p6 cpe:2.3:a:todd_miller:sudo:1.7.2p6:*:*:*:*:*:*:*
todd_miller sudo 1.7.2p7 cpe:2.3:a:todd_miller:sudo:1.7.2p7:*:*:*:*:*:*:*
todd_miller sudo 1.7.3b1 cpe:2.3:a:todd_miller:sudo:1.7.3b1:*:*:*:*:*:*:*
todd_miller sudo 1.7.4 cpe:2.3:a:todd_miller:sudo:1.7.4:*:*:*:*:*:*:*
todd_miller sudo 1.7.4p1 cpe:2.3:a:todd_miller:sudo:1.7.4p1:*:*:*:*:*:*:*
todd_miller sudo 1.7.4p2 cpe:2.3:a:todd_miller:sudo:1.7.4p2:*:*:*:*:*:*:*
todd_miller sudo 1.7.4p3 cpe:2.3:a:todd_miller:sudo:1.7.4p3:*:*:*:*:*:*:*

References for CVE-2010-2956

URL Tags
http://lists.fedoraproject.org/pipermail/package-announce/2010-September/047516.html
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html
http://secunia.com/advisories/40508 Vendor Advisory
http://secunia.com/advisories/41316 Vendor Advisory
http://secunia.com/advisories/42787
http://security.gentoo.org/glsa/glsa-201009-03.xml
http://wiki.rpath.com/Advisories:rPSA-2010-0075
http://www.mandriva.com/security/advisories?name=MDVSA-2010:175
http://www.redhat.com/support/errata/RHSA-2010-0675.html
http://www.securityfocus.com/archive/1/514489/100/0/threaded
http://www.securityfocus.com/archive/1/515545/100/0/threaded
http://www.securityfocus.com/bid/43019
http://www.securitytracker.com/id?1024392
http://www.sudo.ws/sudo/alerts/runas_group.html Vendor Advisory
http://www.ubuntu.com/usn/USN-983-1
http://www.vmware.com/security/advisories/VMSA-2011-0001.html
http://www.vupen.com/english/advisories/2010/2312
http://www.vupen.com/english/advisories/2010/2318
http://www.vupen.com/english/advisories/2010/2320
http://www.vupen.com/english/advisories/2010/2358
http://www.vupen.com/english/advisories/2011/0025
https://bugzilla.redhat.com/show_bug.cgi?id=628628
cvelogic Threat Intelligence