Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Oracle Linux 7 ELSA-2023-0291 Critical: Sudo Arbitrary File Write

oracle
Calendar Grey January 24, 2023
Oracle Linux Logo Esm H88
The Oracle Linux Security Advisory ELSA-2023-0291 pertains to a critical vulnerability in sudo that allows unauthorized file writes on aarch64 systems.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Summary

[1.8.23-10.3] RHEL 7.9.Z ERRATUM - CVE-2023-22809 sudo: arbitrary file write with privileges of the RunAs user Resolves: rhbz#2161222 [1.8.23-10.2] - RHEL 7.9.Z ERRATUM - defaults use_pty plus SELinux ROLE in user specification breaks terminal Resolves: rhbz#1972820 [1.8.23-10.1] - RHEL 7.9.Z ERRATUM - CVE-2021-3156 Resolves: rhbz#1917729

SRPMs

https://oss.oracle.com:443/ol7/SRPMS-updates//sudo-1.8.23-10.el7_9.3.src.rpm

x86_64

aarch64

sudo-1.8.23-10.el7_9.3.aarch64.rpm sudo-devel-1.8.23-10.el7_9.3.aarch64.rpm

Severity
critical
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2023-22809

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here