Описание
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges provided by sudo.
It was discovered that the default sudo configuration preserved the value of INPUTRC from the user's environment, which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges provided by sudo.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | compat-readline43 | Will not fix | ||
Red Hat Enterprise Linux 5 | readline | Will not fix | ||
Red Hat Enterprise Linux 5 | sudo | Will not fix | ||
Red Hat Enterprise Linux 6 | compat-readline5 | Will not fix | ||
Red Hat Enterprise Linux 6 | readline | Will not fix | ||
Red Hat Enterprise Linux 6 | sudo | Will not fix | ||
Red Hat Enterprise Linux 7 | readline | Will not fix | ||
Red Hat JBoss Enterprise Web Server 1 | readline | Will not fix | ||
Red Hat OpenShift Enterprise 2 | readline | Will not fix | ||
Red Hat Enterprise Linux 7 | sudo | Fixed | RHSA-2016:2593 | 03.11.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.6 Low
CVSS2
Связанные уязвимости
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges provided by sudo.
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges provided by sudo.
sudo: It was discovered that the default sudo configuration on Red Hat ...
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges provided by sudo.
ELSA-2016-2593: sudo security, bug fix, and enhancement update (LOW)
EPSS
3.6 Low
CVSS2