Link following in Sudo - CVE-2021-23239
Published: January 12, 2021 / Updated: January 20, 2021
Vulnerability details
The vulnerability allows a local authenticated user to gain access to sensitive information.
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.
Affected software
Gentoo Linux
Arch Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Slackware Linux
Ubuntu
openEuler
Fedora
sudo (Red Hat package)
sudo (Alpine package)
sudo (Ubuntu package)
sudo-ldap (Ubuntu package)
sudo-help
sudo-debugsource
sudo-devel
sudo
sudo-debuginfo
RecoverPoint for Virtual Machines
Tanzu Greenplum for Kubernetes
OpenShift Virtualization
VMware Tanzu Operations Manager
Isolation Segment
VMware Tanzu Application Service for VMs
RSA Authentication Manager
How to mitigate CVE-2021-23239
sudo (Red Hat package) - update to 1.8.29-7.el8
sudo (Alpine package) - update to 1.9.5-r0
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
sudo (Ubuntu package) - addressed in versions 1.8.16-0ubuntu1.10, 1.8.21p2-3ubuntu1.4, 1.8.31-1ubuntu1.2, 1.9.1-1ubuntu1.1
sudo-ldap (Ubuntu package) - addressed in versions 1.8.16-0ubuntu1.10, 1.8.21p2-3ubuntu1.4, 1.8.31-1ubuntu1.2, 1.9.1-1ubuntu1.1
sudo-help - update to 1.9.2-2
sudo-debugsource - update to 1.9.2-2
sudo-devel - update to 1.9.2-2
sudo - update to 1.9.2-2
sudo-debuginfo - update to 1.9.2-2
sudo - addressed in versions 1.9.5p1-1.fc32, 1.9.5p1-1.fc33, 1.9.5p2-1.fc32, 1.9.5p2-1.fc33
Tanzu Greenplum for Kubernetes - update to 2.0.0
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
VMware Tanzu Operations Manager - addressed in versions 2.7.29, 2.9.17, 2.10.6
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11
RSA Authentication Manager - update to 8.5 Patch 3
External References
Related Security Bulletins
- Link following in Sudo
- Link following in sudo (Alpine package)
- Slackware Linux update for sudo
- Arch Linux update for sudo
- Gentoo update for sudo
- Multiple vulnerabilities in VMware Tanzu Products
- Red Hat Enterprise Linux 8 update for sudo
- Ubuntu update for sudo
- openEuler update for sudo
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Virtualization 2.6
- Fedora 33 update for sudo
- Fedora 32 update for sudo
- Fedora 33 update for sudo
- Fedora 32 update for sudo
- RSA Authentication Manager update for third-party components
- Dell RecoverPoint for Virtual Machines update for third-party components