CVE-2021-23240
published 2021-01-12CVE-2021-23240: selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.07%
61.0th percentile
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sudo | < sudo 1.9.5-1 (bookworm) | sudo 1.9.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | sudo-1.9.5p2-2.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | sudo-1.9.5p2-2.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | sudo-debuginfo-1.9.5p2-2.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | sudo-debuginfo-1.9.5p2-2.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| sudo_project | sudo | < 1.8.32 | 1.8.32 |
| sudo_project | sudo | >= 0 < 1.9.5-1 | 1.9.5-1 |
| sudo_project | sudo | >= 0 < 1.9.5-1 | 1.9.5-1 |
| sudo_project | sudo | >= 0 < 1.9.5-1 | 1.9.5-1 |
| sudo_project | sudo | >= 0 < 1.9.5-1 | 1.9.5-1 |
| sudo_project | sudo | >= 1.9.0 < 1.9.5 | 1.9.5 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary f
vendor_msrc·2021-01-12·CVSS 7.8
CVE-2021-23240 [HIGH] CWE-59 selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary f
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 202
Red Hat
sudo: symbolic link attack in SELinux-enabled sudoedit
vendor_redhat·2021-01-11·CVSS 7.8
CVE-2021-23240 [HIGH] CWE-367 sudo: symbolic link attack in SELinux-enabled sudoedit
sudo: symbolic link attack in SELinux-enabled sudoedit
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
A race condition vulnerability was found in the temporary file handling of sudoedit's SELinux RBAC support. On systems where SELinux is enabled, this flaw allows a malicious user with sudoedit permissions to set the owner of an arbitrary file to the user ID of the target user, potentially leading to local privilege escalation. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availabi
Debian
CVE-2021-23240: sudo - selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivi...
vendor_debian·2021·CVSS 7.8
CVE-2021-23240 [HIGH] CVE-2021-23240: sudo - selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivi...
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
Scope: local
bookworm: resolved (fixed in 1.9.5-1)
bullseye: resolved (fixed in 1.9.5-1)
forky: resolved (fixed in 1.9.5-1)
sid: resolved (fixed in 1.9.5-1)
trixie: resolved (fixed in 1.9.5-1)
GHSA
GHSA-q7hf-7qcc-gmg8: selinux_edit_copy_tfiles in sudoedit in Sudo before 1
ghsa_unreviewed·2022-05-24
CVE-2021-23240 [HIGH] CWE-59 GHSA-q7hf-7qcc-gmg8: selinux_edit_copy_tfiles in sudoedit in Sudo before 1
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
OSV
CVE-2021-23240: selinux_edit_copy_tfiles in sudoedit in Sudo before 1
osv·2021-01-12·CVSS 7.8
CVE-2021-23240 [HIGH] CVE-2021-23240: selinux_edit_copy_tfiles in sudoedit in Sudo before 1
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2021-23240https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EE42Y35SMJOLONAIBNYNFC7J44UUZ2Y6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GMY4VSSBIND7VAYSN6T7XIWJRWG4GBB3/https://security.gentoo.org/glsa/202101-33https://security.netapp.com/advisory/ntap-20210129-0010/https://www.sudo.ws/stable.html#1.9.5https://bugzilla.suse.com/show_bug.cgi?id=CVE-2021-23240https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EE42Y35SMJOLONAIBNYNFC7J44UUZ2Y6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GMY4VSSBIND7VAYSN6T7XIWJRWG4GBB3/https://security.gentoo.org/glsa/202101-33https://security.netapp.com/advisory/ntap-20210129-0010/https://www.sudo.ws/stable.html#1.9.5
2021-01-12
Published