sudo-1.9.5p2-7.el9.1

エラータID: AXSA:2023-4872:03

Release date: 
Friday, January 27, 2023 - 12:44
Subject: 
sudo-1.9.5p2-7.el9.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The sudo packages contain the sudo utility which allows system administrators to
provide certain users with the permission to execute privileged commands, which
are used for system management purposes, without having to log in as root.

Security Fix(es):

* sudo: arbitrary file write with privileges of the RunAs user
(CVE-2023-22809)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

CVE-2023-22809
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra
arguments passed in the user-provided environment variables (SUDO_EDITOR,
VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to
the list of files to process. This can lead to privilege escalation. Affected
versions are 1.8.0 through 1.9.12.p1. The problem exists because a
user-specified editor may contain a "--" argument that defeats a protection
mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. sudo-1.9.5p2-7.el9.1.src.rpm
    MD5: 895053b943777285ffd7a157241dbc3c
    SHA-256: f351eaa47b1c1ba984d4e7edaedb01a9f81ae252501d26ed9e17460b59549298
    Size: 3.86 MB

Asianux Server 9 for x86_64
  1. sudo-1.9.5p2-7.el9.1.x86_64.rpm
    MD5: ba4b99fe4ee6b029a94808e8a0023cee
    SHA-256: cdfff52255d9d7c08908d801212f81f5bc0ce7c785484d026528b786ce8bd685
    Size: 1.02 MB
  2. sudo-python-plugin-1.9.5p2-7.el9.1.x86_64.rpm
    MD5: 091118695d8a9f16811560521cb3df47
    SHA-256: 847bb576f35acb19fcef7e80c5fb74700fed84f5ec79fff25e6e76fb7f7ee952
    Size: 53.40 kB