Back

HIGH

sudo: arbitrary file write with privileges of the RunAs user

Published Jan 18, 2023

Description

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.

Affected products

Remediation

Red Hat mitigation

It is possible to prevent a user-specified editor from being used by sudoedit by adding the following line to the sudoers file. ~~~ Defaults!sudoedit env_delete+="SUDO_EDITOR VISUAL EDITOR" ~~~ To restrict the editor when editing specific files, a Cmnd_Alias can be used, for example: ~~~ Cmnd_Alias EDIT_MOTD = sudoedit /etc/motd Defaults!EDIT_MOTD env_delete+="SUDO_EDITOR VISUAL EDITOR" user ALL = EDIT_MOTD ~~~ But if possible please update the affected package as soon as possible.

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 18, 2023
Updated Apr 4, 2025
Reserved Jan 6, 2023
CISA Vulnrichment
Updated Apr 4, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 18, 2023
ENISA EUVD
Assigner mitre
Published Jan 18, 2023
Updated Apr 4, 2025
Exploited since n/a
EUVD-2023-26921