Input validation error in Sudo - CVE-2023-22809

 

Input validation error in Sudo - CVE-2023-22809

Published: January 18, 2023 / Updated: October 25, 2024


Vulnerability identifier: #VU71332
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22809
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists within the sudoedit (aka -e) feature due to insufficient validation of user-supplied input passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR). The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value. A local user can append arbitrary entries to the list of files to process and escalate privileges on the system.


Affected software

Sudo
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Dell Hybrid Client
EMC ECS
cflinuxfs3
PowerStore T
XtremIO X2
EMC Cloud Tiering Appliance
Amazon Linux AMI
Debian Linux
Gentoo Linux
QuTScloud
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server - Extended Life Cycle Support
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Fedora
macOS
VMware Tanzu Application Service for VMs
Isolation Segment
Oracle Communications Diameter Signaling Router
Dell Secure Connect Gateway
Session Smart Router
IBM Spectrum Protect Plus
QVP (QVR Pro appliances)
LANTIME Operating System Firmware (LTOS)
QuTS hero
IBM Integrated Analytics System
IBM QRadar Network Packet Capture
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
sudo (Ubuntu package)
sudo-ldap (Ubuntu package)
sudo (Red Hat package)
sudo-debuginfo
sudo-debugsource
sudo
sudo-devel
sudo-help
sudo (Debian package)
sudo-plugin-python-debuginfo
sudo-plugin-python
sudo-test
app-admin/sudo
redhat-release-virtualization-host (Red Hat package)
IBM Security Guardium
VMware Tanzu Operations Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
QNAP QTS
Dell EMC VxRail Appliance
IBM Qradar SIEM

How to mitigate CVE-2023-22809

Install updates from vendor's website.

Sudo - update to 1.9.12p2
VMware Tanzu Application Service for VMs - addressed in versions 2.11.35, 2.12.24, 2.13.17, 3.0.7
Isolation Segment - addressed in versions 2.11.29, 2.12.19, 2.13.14, 3.0.7
IBM Integrated Analytics System - update to 1.0.31.0
EMC ECS - update to 3.7.0.6
LANTIME Operating System Firmware (LTOS) - update to 7.06.012
sudo (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.8.21p2-3ubuntu1.5, 1.8.31-1ubuntu1.4, 1.9.9-1ubuntu2.2, 1.9.11p3-1ubuntu1.1
sudo-ldap (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.8.21p2-3ubuntu1.5, 1.8.31-1ubuntu1.4, 1.9.9-1ubuntu2.2, 1.9.11p3-1ubuntu1.1
QuTS hero - update to h5.0.1.2348 build 20230324
cflinuxfs3 - update to 0.351.0
sudo (Red Hat package) - addressed in versions 1.8.6p3-29.el6_10.7, 1.8.19p2-12.el7_4.3, 1.8.23-3.el7_6.3, 1.8.23-4.el7_7.4, 1.8.23-10.el7_9.3, 1.8.25p1-8.el8_1.3, 1.8.29-5.el8_2.2, 1.8.29-7.el8_4.2, 1.8.29-8.el8_6.1, 1.8.29-8.el8_7.1, 1.9.5p2-7.el9_0.2, 1.9.5p2-7.el9_1.1
sudo-debuginfo - addressed in versions 1.8.10p3-10.44.1, 1.8.20p2-3.36.1, 1.8.27-4.33.1, 1.8.27-150000.4.38.1, 1.9.5p2-150300.3.19.1, 1.9.9-150400.4.12.1
sudo-debugsource - addressed in versions 1.8.10p3-10.44.1, 1.8.20p2-3.36.1, 1.8.27-4.33.1, 1.8.27-150000.4.38.1, 1.9.5p2-150300.3.19.1, 1.9.9-150400.4.12.1
sudo - addressed in versions 1.8.10p3-10.44.1, 1.8.20p2-3.36.1, 1.8.27-4.33.1, 1.8.27-150000.4.38.1, 1.9.5p2-150300.3.19.1, 1.9.9-150400.4.12.1
sudo - addressed in versions 1.8.23-10, 1.8.29-8
sudo-devel - update to 1.8.23-10
sudo - addressed in versions 1.8.23-10.57, 1.8.23-10.59
sudo-devel - addressed in versions 1.8.27-4.33.1, 1.8.27-150000.4.38.1, 1.9.5p2-150300.3.19.1, 1.9.9-150400.4.12.1
sudo-help - update to 1.9.2-10
sudo-debugsource - update to 1.9.2-10
sudo-debuginfo - update to 1.9.2-10
sudo-devel - update to 1.9.2-10
sudo - update to 1.9.2-10
sudo (Debian package) - update to 1.9.5p2-3+deb11u1
sudo-plugin-python-debuginfo - addressed in versions 1.9.5p2-150300.3.19.1, 1.9.9-150400.4.12.1
sudo-plugin-python - addressed in versions 1.9.5p2-150300.3.19.1, 1.9.9-150400.4.12.1
sudo-test - update to 1.9.9-150400.4.12.1
sudo - update to 1.9.12p2
app-admin/sudo - update to 1.9.12-r1
sudo - addressed in versions 1.9.12-1.p2.fc37, 1.9.12-2.p2.fc36
VMware Tanzu Operations Manager - addressed in versions 2.10.53, 3.0.4
PowerStore T - update to 3.5.0.1-2083289
redhat-release-virtualization-host (Red Hat package) - update to 4.5.3-4.el8ev
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
QNAP QTS - update to 5.0.1.2346 20230322
Dell Secure Connect Gateway - update to 5.14.00.16
Session Smart Router - update to 6.2.3-r2
XtremIO X2 - update to 6.4.2-13
Dell EMC VxRail Appliance - update to 7.0.411
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 6
IBM Spectrum Protect Plus - update to 10.1.14
EMC Cloud Tiering Appliance - update to 13.2.0.2.22
macOS - update to 13.4 22F66

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins