Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-28487

Published: March 16, 2023Last modified: September 30, 2023

Description

Sudo before 1.9.13 does not escape control characters in sudoreplay output.

Severity score breakdown

ParameterValue
Base score5.3
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSsudoFixed (1.9.15_p5-r0)

References

ON THIS PAGE