漏洞信息详情
Sudo 后置链接漏洞
漏洞简介
Sudo是一款使用于类Unix系统的,允许用户通过安全的方式使用特殊的权限执行命令的程序。
sudo 1.9.5之前版本存在后置链接漏洞,该漏洞允许攻击者测试文件系统中任意位置是否存在目录。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.sudo.ws/repos/sudo/rev/ea19d0073c02
参考网址
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/EE42Y35SMJOLONAIBNYNFC7J44UUZ2Y6/
来源:GENTOO
链接:https://security.gentoo.org/glsa/202101-33
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/GMY4VSSBIND7VAYSN6T7XIWJRWG4GBB3/
来源:MISC
链接:https://bugzilla.suse.com/show_bug.cgi?id=CVE-2021-23239
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210129-0010/
来源:CONFIRM
链接:https://www.sudo.ws/stable.html#1.9.5
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-23239
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-23239
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0287/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162685/Red-Hat-Security-Advisory-2021-1723-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2711
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161135/Ubuntu-Security-Notice-USN-4705-1.html
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Sudo-multiple-vulnerabilities-34271
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021052034
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0307/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2160
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6520474
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1702
受影响实体
暂无
补丁
- Sudo 安全漏洞的修复措施<!--2021-1-11-->
还没有评论,来说两句吧...