Link following in Sudo - CVE-2021-23239
Published: January 12, 2021 / Updated: January 20, 2021
Sudo
Detailed vulnerability description
The vulnerability allows a local authenticated user to gain access to sensitive information.
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.