Summary: | <app-admin/sudo-1.9.12_p2: env var mishandling leads to arbitrary file editing | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | base-system |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf | ||
Whiteboard: | B1 [glsa+] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 891405 | ||
Bug Blocks: |
Description
John Helmert III
![]() ![]() ![]() ![]() The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=9221536c0eb35c149399339abe2edcca58c2b091 commit 9221536c0eb35c149399339abe2edcca58c2b091 Author: Sam James <sam@gentoo.org> AuthorDate: 2023-01-18 21:51:42 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2023-01-18 21:51:42 +0000 app-admin/sudo: add 1.9.12_p2 Bug: https://bugs.gentoo.org/891335 Signed-off-by: Sam James <sam@gentoo.org> app-admin/sudo/Manifest | 2 + app-admin/sudo/sudo-1.9.12_p2.ebuild | 286 +++++++++++++++++++++++++++++++++++ 2 files changed, 288 insertions(+) GLSA request filed The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=81c8110bb9b2773a088b16cce1850f93198cb68f commit 81c8110bb9b2773a088b16cce1850f93198cb68f Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2023-05-03 09:53:34 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2023-05-03 09:54:23 +0000 [ GLSA 202305-12 ] sudo: Root Privilege Escalation Bug: https://bugs.gentoo.org/891335 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Sam James <sam@gentoo.org> glsa-202305-12.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) |