First published: Thu Mar 16 2023(Updated: )
Sudo before 1.9.13 does not escape control characters in log messages.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sudo Project Sudo | <1.9.13 | |
redhat/sudo | <1.9.13 | 1.9.13 |
Netapp Active Iq Unified Manager Vmware Vsphere |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2023-28486.
The title of this vulnerability is "Sudo before 1.9.13 does not escape control characters in log messages."
The vulnerability affects Sudo before version 1.9.13.
The severity of CVE-2023-28486 is medium with a CVSS score of 5.3.
To fix the CVE-2023-28486 vulnerability, you should update Sudo to version 1.9.13 or later.