QID 355060
Date Published: 2023-05-18
QID 355060: Amazon Linux Security Advisory for sudo : AL2012-2023-384
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2023-22809:
A vulnerability was found in sudo. Exposure in how sudoedit handles user-provided environment variables leads to arbitrary file writing with privileges of the RunAs user (usually root). The prerequisite for exploitation is that the current user must be authorized by the sudoers policy to edit a file using sudoedit.
2161142: CVE-2023-22809 sudo: arbitrary file write with privileges of the RunAs user
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Administrators are advised to apply the appropriate software updates.
Vendor References
CVEs related to QID 355060
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2023-384 | Amazon Linux Bare Metal |
|