Debian Security Advisory 5321-1

Discussion in 'News Aggregator' started by Packet Storm, 19 Jan 2023.

  1. Packet Storm

    Packet Storm Guest

    Debian Linux Security Advisory 5321-1 - Matthieu Barjole and Victor Cutillas discovered that sudoedit in sudo, a program designed to provide limited super user privileges to specific users, does not properly handle '--' to separate the editor and arguments from files to edit. A local user permitted to edit certain files can take advantage of this flaw to edit a file not permitted by the security policy, resulting in privilege escalation.

    Continue reading...
     

Share This Page

Loading...