In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a – argument that defeats a protection mechanism, e.g., an EDITOR=vim – /path/to/extra/file value.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sudo | Sudo_project | 1.8.0 (including) | 1.9.12 (excluding) |
Sudo | Sudo_project | 1.9.12 (including) | 1.9.12 (including) |
Sudo | Sudo_project | 1.9.12-p1 (including) | 1.9.12-p1 (including) |
Red Hat Enterprise Linux 6 Extended Lifecycle Support | RedHat | sudo-0:1.8.6p3-29.el6_10.7 | * |
Red Hat Enterprise Linux 7 | RedHat | sudo-0:1.8.23-10.el7_9.3 | * |
Red Hat Enterprise Linux 7.4 Advanced Update Support | RedHat | sudo-0:1.8.19p2-12.el7_4.3 | * |
Red Hat Enterprise Linux 7.6 Advanced Update Support | RedHat | sudo-0:1.8.23-3.el7_6.3 | * |
Red Hat Enterprise Linux 7.7 Advanced Update Support | RedHat | sudo-0:1.8.23-4.el7_7.4 | * |
Red Hat Enterprise Linux 7.7 Telco Extended Update Support | RedHat | sudo-0:1.8.23-4.el7_7.4 | * |
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | RedHat | sudo-0:1.8.23-4.el7_7.4 | * |
Red Hat Enterprise Linux 8 | RedHat | sudo-0:1.8.29-8.el8_7.1 | * |
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | RedHat | sudo-0:1.8.25p1-8.el8_1.3 | * |
Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | sudo-0:1.8.29-5.el8_2.2 | * |
Red Hat Enterprise Linux 8.2 Telecommunications Update Service | RedHat | sudo-0:1.8.29-5.el8_2.2 | * |
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | RedHat | sudo-0:1.8.29-5.el8_2.2 | * |
Red Hat Enterprise Linux 8.4 Extended Update Support | RedHat | sudo-0:1.8.29-7.el8_4.2 | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | sudo-0:1.8.29-8.el8_6.1 | * |
Red Hat Enterprise Linux 9 | RedHat | sudo-0:1.9.5p2-7.el9_1.1 | * |
Red Hat Enterprise Linux 9 | RedHat | sudo-0:1.9.5p2-7.el9_1.1 | * |
Red Hat Enterprise Linux 9.0 Extended Update Support | RedHat | sudo-0:1.9.5p2-7.el9_0.2 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | RedHat | redhat-virtualization-host-0:4.5.3-202302150956_8.6 | * |
Sudo | Ubuntu | bionic | * |
Sudo | Ubuntu | devel | * |
Sudo | Ubuntu | esm-infra/xenial | * |
Sudo | Ubuntu | focal | * |
Sudo | Ubuntu | jammy | * |
Sudo | Ubuntu | kinetic | * |
Sudo | Ubuntu | lunar | * |
Sudo | Ubuntu | trusty | * |
Sudo | Ubuntu | trusty/esm | * |
Sudo | Ubuntu | upstream | * |
Sudo | Ubuntu | xenial | * |