SB2023111341 - Slackware Linux update for sudo
Published: November 13, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2023-42456)
The vulnerability allows a remote user to delete arbitrary files on the system.
The vulnerability exists due to insufficient validation certain characters, such as dot (".") and slash ("/") in the username. An attacker with ability tun run the "sudo -k" command can remove arbitrary files on the system given that the attacker has full control over the username on the system.
Remediation
Install update from vendor's website.