CVE-2021-23240
12.01.2021, 09:15
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
Vendor | Product | Version |
---|---|---|
sudo_project | sudo | 𝑥 < 1.8.32 |
sudo_project | sudo | 1.9.0 ≤ 𝑥 < 1.9.5 |
netapp | hci_management_node | - |
netapp | solidfire | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References