A bug was introduced in Sudo’s group matching code in version 1.6.9 when support for matching based on the supplemental group vector was added. This bug may allow certain users listed in the sudoers file to run a command as a different user than their access rule specifies. Sudo versions affected: Sudo versions 1.6.9 up to and including 1.6.9p19. Sudo version 1.7.0 is not affected.