1.270.1. RHSA-2011:0599: Low security and bug fix update
An updated sudo package that fixes one security issue and several bugs is now available for Red Hat Enterprise Linux 6.
The Red Hat Security Response Team has rated this update as having low security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section.
The sudo (superuser do) utility allows system administrators to give certain users the ability to run commands as root.
A flaw was found in the sudo password checking logic. In configurations where the sudoers settings allowed a user to run a command using sudo with only the group ID changed, sudo failed to prompt for the user's password before running the specified command with the elevated group privileges. (CVE-2011-0010)
All users of sudo are advised to upgrade to this updated package, which resolves these issues.