Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-27320

Опубликовано: 28 фев. 2023
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

Sudo before 1.9.13p2 has a double free in the per-command chroot feature.

A double-free vulnerability was found in Sudo in the per-command chroot feature. This flaw exists due to a boundary error when matching a sudoer rule that contains a per-command chroot directive (CHROOT=dir). By sending a specially-crafted request, a local privileged attacker can elevate privileges and execute arbitrary code on the system.

Отчет

The CHROOT support was only added in Sudo v1.9.3 and Sudo v1.9.8 included a fix for a memory leak in the set_cmnd_path() function, which can result in the "user_cmnd" variable being freed twice, but only when processing a sudoers rule that contains a "CHROOT" setting. This does not affect the "chroot" Defaults setting. Only a per-rule "CHROOT" setting will trigger the bug. Hence, it only affects Sudo v1.9.8 through to 1.9.13p1. Red Hat Enterprise Linux - 6, 7, 8, 9 are shipped with lower versions of Sudo that doesn't contains the vulnerable code. Thus, they are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sudoNot affected
Red Hat Enterprise Linux 7sudoNot affected
Red Hat Enterprise Linux 8sudoNot affected
Red Hat Enterprise Linux 9sudoNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-415
https://bugzilla.redhat.com/show_bug.cgi?id=2174218sudo: double free with per-command chroot sudoers rules

EPSS

Процентиль: 40%
0.00181
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
почти 3 года назад

Sudo before 1.9.13p2 has a double free in the per-command chroot feature.

CVSS3: 7.2
nvd
почти 3 года назад

Sudo before 1.9.13p2 has a double free in the per-command chroot feature.

CVSS3: 7.2
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 7.2
debian
почти 3 года назад

Sudo before 1.9.13p2 has a double free in the per-command chroot featu ...

CVSS3: 7.2
github
почти 3 года назад

Sudo before 1.9.13p2 has a double free in the per-command chroot feature.

EPSS

Процентиль: 40%
0.00181
Низкий

6.4 Medium

CVSS3