CVE-2009-0034
Title: Gratisoft Sudo Broken Access Control
Other
Proof Of Concept
No public PoC currently indexed for CVE-2009-0034.
CWE Category
CWE-863
Published Date
Jan 30, 2009
Modified Date
Jun 16, 2026
Exploit Status
Not Found
Score
7.8
CVSS v3.1
Exploit Probability (EPSS)
0.41%
Vulnerability Summary
CVE-2009-0034: parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
Impacted Vendors
Reference Links
http://lists.vmware.com/pipermail/security-announce/2009/000060.html
http://osvdb.org/51736
http://secunia.com/advisories/33753
http://secunia.com/advisories/33840
http://secunia.com/advisories/33885
http://secunia.com/advisories/35766
http://wiki.rpath.com/Advisories:rPSA-2009-0021
http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327
http://www.mandriva.com/security/advisories?name=MDVSA-2009:033
http://www.redhat.com/support/errata/RHSA-2009-0267.html
http://www.securityfocus.com/archive/1/500546/100/0/threaded
http://www.securityfocus.com/archive/1/504849/100/0/threaded
http://www.securityfocus.com/bid/33517
http://www.securitytracker.com/id?1021688
http://www.sudo.ws/cgi-bin/cvsweb/sudo/parse.c.diff?r1=1.160.2.21&r2=1.160.2.22&f=h
http://www.vmware.com/security/advisories/VMSA-2009-0009.html
http://www.vupen.com/english/advisories/2009/1865
https://bugzilla.novell.com/show_bug.cgi?id=468923
https://issues.rpath.com/browse/RPL-2954
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10856
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6462
http://lists.vmware.com/pipermail/security-announce/2009/000060.html
http://osvdb.org/51736
http://secunia.com/advisories/33753
http://secunia.com/advisories/33840
http://secunia.com/advisories/33885
http://secunia.com/advisories/35766
http://wiki.rpath.com/Advisories:rPSA-2009-0021
http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327
http://www.mandriva.com/security/advisories?name=MDVSA-2009:033
http://www.redhat.com/support/errata/RHSA-2009-0267.html
http://www.securityfocus.com/archive/1/500546/100/0/threaded
http://www.securityfocus.com/archive/1/504849/100/0/threaded
http://www.securityfocus.com/bid/33517
http://www.securitytracker.com/id?1021688
http://www.sudo.ws/cgi-bin/cvsweb/sudo/parse.c.diff?r1=1.160.2.21&r2=1.160.2.22&f=h
http://www.vmware.com/security/advisories/VMSA-2009-0009.html
http://www.vupen.com/english/advisories/2009/1865
https://bugzilla.novell.com/show_bug.cgi?id=468923
https://issues.rpath.com/browse/RPL-2954
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10856
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6462
CVSS v3.1
Source Entity
[email protected]
Severity
HIGH
7.8
Attack Vector
LOCAL
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
6.9
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:L/AC:M/Au:N/C:C/I:C/A:C
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2009-0034 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
LOCAL
Complexity
LOW
Privileges
N/A
Interaction
NONE
CVSS Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Stack
No specific products linked.