Link following in Sudo - CVE-2021-23240

 

Link following in Sudo - CVE-2021-23240

Published: January 12, 2021 / Updated: January 20, 2021


Vulnerability identifier: #VU49884
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23240
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.


Affected software

Sudo
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Slackware Linux
openEuler
Fedora
sudo (Red Hat package)
sudo (Alpine package)
sudo
sudo-debuginfo
sudo-debugsource
sudo-devel
sudo-help
OpenShift Virtualization
Dell EMC VxRail Appliance
RSA Authentication Manager
Juniper Cloud Native Router
Junos cRPD

How to mitigate CVE-2021-23240

Install update from vendor's website.

Sudo - update to 1.9.5
sudo (Red Hat package) - update to 1.8.29-7.el8
sudo (Alpine package) - update to 1.9.5-r0
sudo - update to 1.9.2-2
sudo-debuginfo - update to 1.9.2-2
sudo-debugsource - update to 1.9.2-2
sudo-devel - update to 1.9.2-2
sudo-help - update to 1.9.2-2
sudo - addressed in versions 1.9.5p1-1.fc32, 1.9.5p1-1.fc33
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
Dell EMC VxRail Appliance - update to 7.0.240
RSA Authentication Manager - update to 8.5 Patch 3
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins