ALT-PU-2023-1357-1
Closed vulnerabilities
Published: 2023-02-28
BDU:2023-01183
Уязвимость функции set_cmnd_path() программы системного администрирования Sudo, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (5.5)
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References:
Published: 2023-02-28
Modified: 2025-03-22
Modified: 2025-03-22
CVE-2023-27320
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Severity: HIGH (7.2)
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
References:
- [oss-security] 20230301 Re: sudo: double free with per-command chroot sudoers rules
- [oss-security] 20230301 Re: sudo: double free with per-command chroot sudoers rules
- FEDORA-2023-cb5df36beb
- FEDORA-2023-cb5df36beb
- FEDORA-2023-d2d6ec2a32
- FEDORA-2023-d2d6ec2a32
- FEDORA-2023-11c9d868ca
- FEDORA-2023-11c9d868ca
- GLSA-202309-12
- GLSA-202309-12
- https://security.netapp.com/advisory/ntap-20230413-0009/
- https://security.netapp.com/advisory/ntap-20230413-0009/
- https://www.openwall.com/lists/oss-security/2023/02/28/1
- https://www.openwall.com/lists/oss-security/2023/02/28/1
- https://www.sudo.ws/releases/stable/#1.9.13p2
- https://www.sudo.ws/releases/stable/#1.9.13p2
Published: 2023-03-16
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-28486
Sudo before 1.9.13 does not escape control characters in log messages.
Severity: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References:
- https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13
- [debian-lts-announce] 20240203 [SECURITY] [DLA 3732-1] sudo security update
- GLSA-202309-12
- https://security.netapp.com/advisory/ntap-20230420-0002/
- https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca
- https://security.netapp.com/advisory/ntap-20230420-0002/
- GLSA-202309-12
- [debian-lts-announce] 20240203 [SECURITY] [DLA 3732-1] sudo security update
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13
Published: 2023-03-16
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-28487
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
Severity: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References:
- https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13
- [debian-lts-announce] 20240203 [SECURITY] [DLA 3732-1] sudo security update
- GLSA-202309-12
- https://security.netapp.com/advisory/ntap-20230420-0002/
- https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca
- https://security.netapp.com/advisory/ntap-20230420-0002/
- GLSA-202309-12
- [debian-lts-announce] 20240203 [SECURITY] [DLA 3732-1] sudo security update
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13