Total vulnerabilities in the database
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
Software | From | Fixed in |
---|---|---|
sudo_project / sudo | - | 1.8.32 |
sudo_project / sudo | 1.9.0 | 1.9.5 |
fedoraproject / fedora | 32 | 32.x |
fedoraproject / fedora | 33 | 33.x |