CVE-2021-23239: Race Condition
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudoedit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23239?
CVE-2021-23239 is a vulnerability in the sudoedit personality of Sudo before version 1.9.5 that may allow a local unprivileged user to perform arbitrary directory-existence tests.
How does CVE-2021-23239 affect Sudo?
CVE-2021-23239 affects Sudo versions before 1.9.5.
What is the severity of CVE-2021-23239?
CVE-2021-23239 has a severity level of Low with a score of 2.5.
Which software are affected by CVE-2021-23239?
Sudo versions before 1.9.5, Netapp Cloud Backup, Netapp Hci Management Node, Netapp Solidfire, Fedora 32, Fedora 33, Debian Linux 10.0 are affected by CVE-2021-23239.
How can the CVE-2021-23239 vulnerability be mitigated?
To mitigate the CVE-2021-23239 vulnerability, users should update their Sudo installations to version 1.9.5 or later.