shield
Security update for sudo
SUSE-SLE-Micro-5.4-2023-1665
This update for sudo fixes the following issue: Security issues: - CVE-2023-28486: Fixed sudo does not escape control characters in log messages. (bsc#1209362) - CVE-2023-28487: Fixed sudo does not escape control characters in sudoreplay output. (bsc#1209361) - CVE-2023-27320: Fixed a potential security issue with a double free with per-command chroot sudoers rules (bsc#1208595). Bug fixes: - Fix a situation where "sudo -U otheruser -l" would dereference a NULL pointer (bsc#1206483) - If NOPASSWD is specified, don't ask for password if command is not found (bsc#1206772). - Do not re-enable the reader when flushing the buffers as part of pty_finish() (bsc#1203201).
-
Release DateMar 29 2023
-
ReferencesBugzilla: 1206483, 1206772, 1203201, 1209361, 1208595, 1209362
CVEs: CVE-2023-27320, CVE-2023-28486, CVE-2023-28487 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Micro 5.4 aarch64
-
Packages
SUSE Linux Enterprise Micro 5.4 x86_64
-
Packages
SUSE Linux Enterprise Micro 5.4 s390x
-
Packages