First published: Thu Mar 16 2023(Updated: )
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sudo Project Sudo | <1.9.13 | |
redhat/sudo | <1.9.13 | 1.9.13 |
Netapp Active Iq Unified Manager Vmware Vsphere |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2023-28487.
The title of this vulnerability is 'Sudo before 1.9.13 does not escape control characters in sudoreplay output.'
The description of this vulnerability is 'Sudo before 1.9.13 does not escape control characters in sudoreplay output.'
The software affected by this vulnerability is Sudo Project Sudo before version 1.9.13.
The severity of this vulnerability is medium (5.3).
To fix this vulnerability, update to Sudo version 1.9.13 or later.
You can find more information about this vulnerability at the following references: [Link to GitHub commit](https://github.com/sudo-project/sudo/commit/334daf92b31b79ce68ed75e2ee14fca265f029ca), [Link to GitHub release](https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_13), [Link to Gentoo advisory](https://security.gentoo.org/glsa/202309-12).
The Common Weakness Enumeration (CWE) ID for this vulnerability is 116.