The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.
| Software | From | Fixed in |
|---|---|---|
| sudo_project / sudo | - | 1.8.32 |
| sudo_project / sudo | 1.9.0 | 1.9.5 |
| fedoraproject / fedora | 32 | 32.x |
| fedoraproject / fedora | 33 | 33.x |
| debian / debian_linux | 10.0 | 10.0.x |