Ubuntu Security Notice USN-5811-1

Discussion in 'News Aggregator' started by Packet Storm, 20 Jan 2023.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 5811-1 - Matthieu Barjole and Victor Cutillas discovered that Sudo incorrectly handled user-specified editors when using the sudoedit command. A local attacker that has permission to use the sudoedit command could possibly use this issue to edit arbitrary files. It was discovered that the Protobuf-c library, used by Sudo, incorrectly handled certain arithmetic shifts. An attacker could possibly use this issue to cause Sudo to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS.

    Continue reading...
     

Share This Page

Loading...