Описание
Security update for sudo
This update for sudo fixes the following issues:
- CVE-2023-28486: Fixed missing control characters escaping in log messages (bsc#1209362).
- CVE-2023-28487: Fixed missing control characters escaping in sudoreplay output (bsc#1209361).
Список пакетов
SUSE Linux Enterprise Server 12 SP4-ESPOS
sudo-1.8.20p2-3.39.1
SUSE Linux Enterprise Server 12 SP4-LTSS
sudo-1.8.20p2-3.39.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
sudo-1.8.20p2-3.39.1
SUSE OpenStack Cloud 9
sudo-1.8.20p2-3.39.1
SUSE OpenStack Cloud Crowbar 9
sudo-1.8.20p2-3.39.1
Ссылки
- Link for SUSE-SU-2023:1700-1
- E-Mail link for SUSE-SU-2023:1700-1
- SUSE Security Ratings
- SUSE Bug 1209361
- SUSE Bug 1209362
- SUSE CVE CVE-2023-28486 page
- SUSE CVE CVE-2023-28487 page
Описание
Sudo before 1.9.13 does not escape control characters in log messages.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP4-ESPOS:sudo-1.8.20p2-3.39.1
SUSE Linux Enterprise Server 12 SP4-LTSS:sudo-1.8.20p2-3.39.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4:sudo-1.8.20p2-3.39.1
SUSE OpenStack Cloud 9:sudo-1.8.20p2-3.39.1
Ссылки
- CVE-2023-28486
- SUSE Bug 1209362
Описание
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP4-ESPOS:sudo-1.8.20p2-3.39.1
SUSE Linux Enterprise Server 12 SP4-LTSS:sudo-1.8.20p2-3.39.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4:sudo-1.8.20p2-3.39.1
SUSE OpenStack Cloud 9:sudo-1.8.20p2-3.39.1
Ссылки
- CVE-2023-28487
- SUSE Bug 1209361