Vulnerability Description
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sudo Project | Sudo | < 1.8.32 |
| Netapp | Cloud Backup | - |
| Netapp | Hci Management Node | - |
| Netapp | Solidfire | - |
| Fedoraproject | Fedora | 32 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2021-23239ExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00007.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202101-33Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210129-0010/Third Party Advisory
- https://www.sudo.ws/stable.html#1.9.5Release NotesVendor Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2021-23239ExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00007.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202101-33Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210129-0010/Third Party Advisory
- https://www.sudo.ws/stable.html#1.9.5Release NotesVendor Advisory
FAQ
What is CVE-2021-23239?
CVE-2021-23239 is a vulnerability with a CVSS score of 2.5 (LOW). The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled ...
How severe is CVE-2021-23239?
CVE-2021-23239 has been rated LOW with a CVSS base score of 2.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23239?
Check the references section above for vendor advisories and patch information. Affected products include: Sudo Project Sudo, Netapp Cloud Backup, Netapp Hci Management Node, Netapp Solidfire, Fedoraproject Fedora.