Vulnerabilities > CVE-2023-27320 - Double Free vulnerability in multiple products
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 14 | |
OS | 3 |
Common Weakness Enumeration (CWE)
References
- https://www.sudo.ws/releases/stable/#1.9.13p2
- https://www.openwall.com/lists/oss-security/2023/02/28/1
- http://www.openwall.com/lists/oss-security/2023/03/01/8
- https://security.netapp.com/advisory/ntap-20230413-0009/
- https://security.gentoo.org/glsa/202309-12
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLXMRAMXC3BYL4DNKVTK3V6JDMUXZ7B/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6VW24YGXJYI4NZ5HZPQCF4MCE7766AU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/332KN4QI6QXB7NI7SWSJ2EQJKWIILFN6/