sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.
openSUSE 11.0 openSUSE 11.1 openSUSE 11.2 SUSE Linux Enterprise 11 Moblin 2.0 SUSE Linux Enterprise 11 Moblin 2.1 SUSE Linux Enterprise Desktop 11 GA SUSE Linux Enterprise Server 11 SUSE Linux Enterprise Server 11 GA SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP3 SUSE Linux Enterprise Server 11 SP4 SUSE Linux Enterprise Server for SAP Applications 11