#VU49883 Link following in Sudo - CVE-2021-23239
Published: January 12, 2021 / Updated: January 20, 2021
Sudo
Sudo
Description
The vulnerability allows a local authenticated user to gain access to sensitive information.
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.