VDB
BDU%3A2024-01160
BDU%3A2024-01160
PUBLISHED
CVSS 6 MEDIUM
Уязвимость программы системного администрирования Sudo, связанная с недостатками процедуры аутентификации, позволяющая нарушителю повысить свои привилегии
Risk Scores
CVSS 2.0
6
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», АО «ИВК», Fedora Project, NetApp Inc., Todd C. Miller, ООО «НЦПР» | Red Hat Enterprise Linux, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Software Development Kit, Suse Linux Enterprise Server, SUSE Linux Enterprise Module for Basesystem, SUSE CaaS Platform, SUSE OpenStack Cloud Crowbar, Debian GNU/Linux, SUSE Enterprise Storage, HPE Helion Openstack, SUSE Linux Enterprise High Performance Computing, openSUSE Tumbleweed, SUSE Linux Enterprise Server for Raspberry Pi, SUSE Manager Proxy, SUSE Manager Server, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise Micro, Альт 8 СП (запись в едином реестре российских программ №4305), SUSE Linux Enterprise Real Time, SUSE Manager Retail Branch Server, Fedora, АЛЬТ СП 10, NetApp SolidFire & HCI Storage Node, NetApp SolidFire & HCI Management Node, NetApp HCI Compute Node BIOS, Sudo, ONTAP Tools for VMware vSphere, МСВСфера |
Timeline
- Feb 13, 2024 CVE Published
- Nov 19, 2025 CVE Updated
References
- https://github.com/sudo-project/sudo/commit/7873f8334c8d31031f8cfa83bd97ac6029309e4f url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6XMRUJCPII4MPWG43HTYR76DGLEYEFZ/ url
- https://security.netapp.com/advisory/ntap-20240208-0002/ url
- https://security-tracker.debian.org/tracker/CVE-2023-42465 url
- https://access.redhat.com/security/cve/CVE-2023-42465 url
- https://www.suse.com/security/cve/CVE-2023-42465.html url
- https://www.openwall.com/lists/oss-security/2023/12/21/9 url
- https://cve.basealt.ru/report-01012024-c10f1.html url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://errata.msvsphere-os.ru/definition/9/INFCSA-2024:0811?lang=ru url