#VU49884 Link following in Sudo - CVE-2021-23240
Published: January 12, 2021 / Updated: January 20, 2021
Sudo
Sudo
Description
The vulnerability allows a local authenticated user to execute arbitrary code.
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.