CVE-2023-28487 (https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca): Sudo before 1.9.13 does not escape control characters in sudoreplay output. CVE-2023-28486 (https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca): Sudo before 1.9.13 does not escape control characters in log messages.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=0654687f767ea0ec35b7400d19b29574fbdb4c2f commit 0654687f767ea0ec35b7400d19b29574fbdb4c2f Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2023-09-29 12:15:42 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2023-09-29 12:16:41 +0000 [ GLSA 202309-12 ] sudo: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/898510 Bug: https://bugs.gentoo.org/905322 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202309-12.xml | 45 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 45 insertions(+)