VMware Security Advisory 2011-0001 - ESX 4.0 Service Console OS (COS) updates for glibc, sudo, and openldap packages.
c46f8a177cb54cdf53c56e8c0fc1617a7a611c96438fab66c017b274544829ed
Mandriva Linux Security Advisory 2010-175 - Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a -u root sequence. The updated packages have been patched to correct this issue.
a2bbd5c115c98d917d40c978584d00aaf8a43d678490fb1e3a41bf3c453d8677
Ubuntu Security Notice 983-1 - Markus Wuethrich discovered that sudo did not always verify the user when a group was specified in the Runas_Spec. A local attacker could exploit this to execute arbitrary code as root if sudo was configured to allow the attacker to use a program as a group when the attacker was not a part of that group.
62d38ec064d0f0ae54ffdd39f4c5cebe6d080d478403d1d548b88dc150afceba
Gentoo Linux Security Advisory 201009-3 - The secure path feature and group handling in sudo allow local attackers to escalate privileges. Versions less than 1.7.4_p3-r1 are affected.
64d26ed806b78f1b66f52278ea929c7c037d7db811b81866bdff928a6b17c6fb