Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-23239

Опубликовано: 12 янв. 2021
Источник: debian
EPSS Низкий

Описание

The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sudofixed1.9.5-1package
sudono-dsastretchpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2021/01/11/2

  • https://www.sudo.ws/repos/sudo/rev/ea19d0073c02

EPSS

Процентиль: 19%
0.00062
Низкий

Связанные уязвимости

CVSS3: 2.5
ubuntu
почти 5 лет назад

The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.

CVSS3: 2.5
redhat
почти 5 лет назад

The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.

CVSS3: 2.5
nvd
почти 5 лет назад

The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.

CVSS3: 2.5
msrc
почти 5 лет назад

The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.

CVSS3: 2.5
github
больше 3 лет назад

The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.

EPSS

Процентиль: 19%
0.00062
Низкий