Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Mageia 8: MGASA-2023-0133 Moderate: Sudo Control Character Escaping

mageia
Calendar Grey April 11, 2023
Dist Mageia Esm H88
Recent updates to the sudo packages address security vulnerabilities within Mageia 8 related to the improper handling of control character escaping prior to version 1.9.13.
Sudo before 1.9.13 does not escape control characters in log messages

Summary

Sudo before 1.9.13 does not escape control characters in log messages. (CVE-2023-28486) Sudo before 1.9.13 does not escape control characters in sudoreplay output. (CVE-2023-28487)

References

- https://bugs.mageia.org/show_bug.cgi?id=31738

- https://lists.suse.com/pipermail/sle-security-updates/2023-March/014226.html

- https://www.cve.org/CVERecord?id=CVE-2023-28486

- https://www.cve.org/CVERecord?id=CVE-2023-28487

Resolution

SRPMS

- 8/core/sudo-1.9.5p2-2.3.mga8

Publication date: 11 Apr 2023
URL: https://advisories.mageia.org/MGASA-2023-0133.html
Type: security
CVE: CVE-2023-28486, CVE-2023-28487

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here