Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
References
Link | Resource |
---|---|
https://www.sudo.ws/releases/stable/#1.9.13p2 | Release Notes |
https://www.openwall.com/lists/oss-security/2023/02/28/1 | Exploit Mailing List Third Party Advisory |
http://www.openwall.com/lists/oss-security/2023/03/01/8 | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FPLXMRAMXC3BYL4DNKVTK3V6JDMUXZ7B/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6VW24YGXJYI4NZ5HZPQCF4MCE7766AU/ | |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/332KN4QI6QXB7NI7SWSJ2EQJKWIILFN6/ |
Information
Published : 2023-02-28 10:15
Updated : 2023-03-18 00:15
NVD link : CVE-2023-27320
Mitre link : CVE-2023-27320
JSON object : View
CWE
CWE-415
Double Free
Products Affected
sudo_project
- sudo
fedoraproject
- fedora