← Back

CVE-2021-23240

nvd nist
Published: Jan 12, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.

Affected (6)

1 product
Sudo
2 products
Hci Management Node
Solidfire
1 product
Fedora
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Sudo Project
Before 1.8.32
From 1.9.0 to 1.9.5
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33

References (16)

Source: cve@mitre.org
ExploitIssue TrackingPatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.