OESA-2024-1071
Dashboard / Vulnerabilities / OESA-2024-1071
Summary: sudo security update
Details: Sudo is a program designed to allow a sysadmin to give limited root privileges to users and log root activity. The basic philosophy is to give as few privileges as possible but still allow people to get their work done. Security Fix(es): Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.(CVE-2023-42465)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1071, https://nvd.nist.gov/vuln/detail/CVE-2023-42465
Affected packages
Package
Name: sudo
Purl: pkg:rpm/openEuler/sudo&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
