Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:1659-1

Опубликовано: 29 мар. 2023
Источник: suse-cvrf

Описание

Security update for sudo

This update for sudo fixes the following issue:

Security fixes:

  • CVE-2023-28486: Fixed missing control characters escaping in log messages (bsc#1209362).
  • CVE-2023-28487: Fixed missing control characters escaping in sudoreplay output (bsc#1209361).

Other fixes:

  • Fix a situation where 'sudo -U otheruser -l' would dereference a NULL pointer (bsc#1206483).
  • Do not re-enable the reader when flushing the buffers as part of pty_finish() (bsc#1203201).

Список пакетов

Image SLES12-SP5-Azure-BYOS
sudo-1.8.27-4.38.1
Image SLES12-SP5-Azure-Basic-On-Demand
sudo-1.8.27-4.38.1
Image SLES12-SP5-Azure-HPC-BYOS
sudo-1.8.27-4.38.1
Image SLES12-SP5-Azure-HPC-On-Demand
sudo-1.8.27-4.38.1
Image SLES12-SP5-Azure-SAP-BYOS
sudo-1.8.27-4.38.1
Image SLES12-SP5-Azure-SAP-On-Demand
sudo-1.8.27-4.38.1
Image SLES12-SP5-Azure-Standard-On-Demand
sudo-1.8.27-4.38.1
Image SLES12-SP5-EC2-BYOS
sudo-1.8.27-4.38.1
Image SLES12-SP5-EC2-ECS-On-Demand
sudo-1.8.27-4.38.1
Image SLES12-SP5-EC2-On-Demand
sudo-1.8.27-4.38.1
Image SLES12-SP5-EC2-SAP-BYOS
sudo-1.8.27-4.38.1
Image SLES12-SP5-EC2-SAP-On-Demand
sudo-1.8.27-4.38.1
Image SLES12-SP5-GCE-BYOS
sudo-1.8.27-4.38.1
Image SLES12-SP5-GCE-On-Demand
sudo-1.8.27-4.38.1
Image SLES12-SP5-GCE-SAP-BYOS
sudo-1.8.27-4.38.1
Image SLES12-SP5-GCE-SAP-On-Demand
sudo-1.8.27-4.38.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
sudo-1.8.27-4.38.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
sudo-1.8.27-4.38.1
SUSE Linux Enterprise Server 12 SP5
sudo-1.8.27-4.38.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
sudo-1.8.27-4.38.1
SUSE Linux Enterprise Software Development Kit 12 SP5
sudo-devel-1.8.27-4.38.1

Описание

Sudo before 1.9.13 does not escape control characters in log messages.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:sudo-1.8.27-4.38.1
Image SLES12-SP5-Azure-Basic-On-Demand:sudo-1.8.27-4.38.1
Image SLES12-SP5-Azure-HPC-BYOS:sudo-1.8.27-4.38.1
Image SLES12-SP5-Azure-HPC-On-Demand:sudo-1.8.27-4.38.1

Ссылки

Описание

Sudo before 1.9.13 does not escape control characters in sudoreplay output.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:sudo-1.8.27-4.38.1
Image SLES12-SP5-Azure-Basic-On-Demand:sudo-1.8.27-4.38.1
Image SLES12-SP5-Azure-HPC-BYOS:sudo-1.8.27-4.38.1
Image SLES12-SP5-Azure-HPC-On-Demand:sudo-1.8.27-4.38.1

Ссылки
Уязвимость SUSE-SU-2023:1659-1