CVE-2021-23240 PUBLISHED

selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.

EPSS 0.22% · 45.0th percentile

Risk Scores

EPSS Score
0.22%
45.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSsudo1.8.16-0ubuntu1.6, 1.8.16-0ubuntu1.9, 1.8.16-0ubuntu1.8
Ubuntu:Pro:18.04:LTSsudo1.8.21p2-3ubuntu1.6+esm1, 1.8.21p2-3ubuntu1.6, 1.8.21p2-3ubuntu1.5
Ubuntu:Pro:20.04:LTSsudo1.8.31-1ubuntu1.5+esm1, 0, 1.8.27-1ubuntu4
Ubuntu:Pro:14.04:LTSsudo1.8.9p5-1ubuntu1.3, 1.8.9p5-1ubuntu1.2, 1.8.9p5-1ubuntu1.1

Timeline

References

Open in Interactive Console →