Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Mageia 8: MGASA-2023-0133 Moderate: Sudo Control Character Escaping

mageia
Calendar Grey April 11, 2023
Scroller Mageia
Recent updates to the sudo packages address security vulnerabilities within Mageia 8 related to the improper handling of control character escaping prior to version 1.9.13.
Sudo before 1.9.13 does not escape control characters in log messages

Summary

Sudo before 1.9.13 does not escape control characters in log messages. (CVE-2023-28486) Sudo before 1.9.13 does not escape control characters in sudoreplay output. (CVE-2023-28487)

References

- https://bugs.mageia.org/show_bug.cgi?id=31738

- https://lists.suse.com/pipermail/sle-security-updates/2023-March/014226.html

- https://www.cve.org/CVERecord?id=CVE-2023-28486

- https://www.cve.org/CVERecord?id=CVE-2023-28487

Resolution

SRPMS

- 8/core/sudo-1.9.5p2-2.3.mga8

Publication date: 11 Apr 2023
URL: https://advisories.mageia.org/MGASA-2023-0133.html
Type: security
CVE: CVE-2023-28486, CVE-2023-28487

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.