sudo: arbitrary file write with privileges of the RunAs user
Published Jan 18, 2023
7.8
HIGHCVSS 3.1
EPSS 55.37%
Description
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.
Affected products
No data.
Configuration 1
- ≥ 1.8.0 · < 1.9.12
- 1.9.12
- 1.9.12
Configuration 2
- 10.0
- 11.0
Configuration 3
- 36
- 37
No data.
Red Hat Enterprise Linux 6 Extended Lifecycle Support
sudo-0:1.8.6p3-29.el6_10.7
Fixed · RHSA-2023:0287
Red Hat Enterprise Linux 7
sudo-0:1.8.23-10.el7_9.3
Fixed · RHSA-2023:0291
Red Hat Enterprise Linux 7.4 Advanced Update Support
sudo-0:1.8.19p2-12.el7_4.3
Fixed · RHSA-2023:3264
Red Hat Enterprise Linux 7.6 Advanced Update Support
sudo-0:1.8.23-3.el7_6.3
Fixed · RHSA-2023:3262
Red Hat Enterprise Linux 7.7 Advanced Update Support
sudo-0:1.8.23-4.el7_7.4
Fixed · RHSA-2023:3276
Red Hat Enterprise Linux 7.7 Telco Extended Update Support
sudo-0:1.8.23-4.el7_7.4
Fixed · RHSA-2023:3276
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
sudo-0:1.8.23-4.el7_7.4
Fixed · RHSA-2023:3276
Red Hat Enterprise Linux 8
sudo-0:1.8.29-8.el8_7.1
Fixed · RHSA-2023:0284
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
sudo-0:1.8.25p1-8.el8_1.3
Fixed · RHSA-2023:0280
Red Hat Enterprise Linux 8.2 Advanced Update Support
sudo-0:1.8.29-5.el8_2.2
Fixed · RHSA-2023:0292
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
sudo-0:1.8.29-5.el8_2.2
Fixed · RHSA-2023:0292
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
sudo-0:1.8.29-5.el8_2.2
Fixed · RHSA-2023:0292
Red Hat Enterprise Linux 8.4 Extended Update Support
sudo-0:1.8.29-7.el8_4.2
Fixed · RHSA-2023:0293
Red Hat Enterprise Linux 8.6 Extended Update Support
sudo-0:1.8.29-8.el8_6.1
Fixed · RHSA-2023:0283
Red Hat Enterprise Linux 9
sudo-0:1.9.5p2-7.el9_1.1
Fixed · RHSA-2023:0282
Red Hat Enterprise Linux 9
sudo-0:1.9.5p2-7.el9_1.1
Fixed · RHSA-2023:0282
Red Hat Enterprise Linux 9.0 Extended Update Support
sudo-0:1.9.5p2-7.el9_0.2
Fixed · RHSA-2023:0281
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.5.3-202302150956_8.6
Fixed · RHSA-2023:0859
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Extended Lifecycle Support | sudo-0:1.8.6p3-29.el6_10.7 | Fixed | RHSA-2023:0287 |
| Red Hat Enterprise Linux 7 | sudo-0:1.8.23-10.el7_9.3 | Fixed | RHSA-2023:0291 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | sudo-0:1.8.19p2-12.el7_4.3 | Fixed | RHSA-2023:3264 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | sudo-0:1.8.23-3.el7_6.3 | Fixed | RHSA-2023:3262 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | sudo-0:1.8.23-4.el7_7.4 | Fixed | RHSA-2023:3276 |
| Red Hat Enterprise Linux 7.7 Telco Extended Update Support | sudo-0:1.8.23-4.el7_7.4 | Fixed | RHSA-2023:3276 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | sudo-0:1.8.23-4.el7_7.4 | Fixed | RHSA-2023:3276 |
| Red Hat Enterprise Linux 8 | sudo-0:1.8.29-8.el8_7.1 | Fixed | RHSA-2023:0284 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | sudo-0:1.8.25p1-8.el8_1.3 | Fixed | RHSA-2023:0280 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | sudo-0:1.8.29-5.el8_2.2 | Fixed | RHSA-2023:0292 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | sudo-0:1.8.29-5.el8_2.2 | Fixed | RHSA-2023:0292 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | sudo-0:1.8.29-5.el8_2.2 | Fixed | RHSA-2023:0292 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | sudo-0:1.8.29-7.el8_4.2 | Fixed | RHSA-2023:0293 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | sudo-0:1.8.29-8.el8_6.1 | Fixed | RHSA-2023:0283 |
| Red Hat Enterprise Linux 9 | sudo-0:1.9.5p2-7.el9_1.1 | Fixed | RHSA-2023:0282 |
| Red Hat Enterprise Linux 9 | sudo-0:1.9.5p2-7.el9_1.1 | Fixed | RHSA-2023:0282 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | sudo-0:1.9.5p2-7.el9_0.2 | Fixed | RHSA-2023:0281 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.5.3-202302150956_8.6 | Fixed | RHSA-2023:0859 |
No package ranges for this CVE.
Remediation
Red Hat mitigation
It is possible to prevent a user-specified editor from being used by sudoedit by adding the following line to the sudoers file. ~~~ Defaults!sudoedit env_delete+="SUDO_EDITOR VISUAL EDITOR" ~~~ To restrict the editor when editing specific files, a Cmnd_Alias can be used, for example: ~~~ Cmnd_Alias EDIT_MOTD = sudoedit /etc/motd Defaults!EDIT_MOTD env_delete+="SUDO_EDITOR VISUAL EDITOR" user ALL = EDIT_MOTD ~~~ But if possible please update the affected package as soon as possible.
References (20)
- http://packetstormsecurity.com/files/171644/sudo-1.9.12p1-Privilege-Escalation.html Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/172509/Sudoedit-Extra-Arguments-Privilege-Escalation.html Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/174234/Cisco-ThousandEyes-Enterprise-Agent-Virtual-Appliance-Arbitrary-File-Modification.html Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2023/Aug/21 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/01/19/1 mailing-listExploitMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-22809 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2161142 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-26921 Advisory
- https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_12p2
- https://lists.debian.org/debian-lts-announce/2023/01/msg00012.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2QDGFCGAV5QRJCE6IXRXIS4XJHS57DDH/ vendor-advisoryMailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G4YNBTTKTRT2ME3NTSXAPTOKYUE47XHZ/ vendor-advisoryMailing List
- https://nvd.nist.gov/vuln/detail/CVE-2023-22809
- https://security.gentoo.org/glsa/202305-12 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230127-0015/ Third Party Advisory
- https://support.apple.com/kb/HT213758 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-22809
- https://www.debian.org/security/2023/dsa-5321 vendor-advisoryThird Party Advisory
- https://www.sudo.ws/security/advisories/sudoedit_any/ ExploitMitigationVendor Advisory
- https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf ExploitMitigationTechnical DescriptionThird Party Advisory
Change history (0)
No recorded changes yet.