发布时间: 2025年7月4日
修改时间: 2025年7月11日
A vulnerability has been found in Todd Miller sudo 1.9.14/1.9.15/1.9.16/1.9.17 (Operating System Utility Software) and classified as critical.The manipulation of the argument -R/--chroot with an unknown input leads to a unknown weakness. The CWE definition for the vulnerability is CWE-284. The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.As an impact it is known to affect confidentiality, integrity, and availability.Applying the patch 1.9.17p1 is able to eliminate this problem.
NVD | openEuler | |
---|---|---|
Confidentiality | High | High |
Attack Vector | Local | Local |
CVSS评分 | 7.8 | 9.3 |
Attack Complexity | Low | Low |
Privileges Required | Low | None |
Scope | Unchanged | Changed |
Integrity | High | High |
User Interaction | None | None |
Availability | High | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2025-2579 | sudo security update | 2025年7月3日 |
KylinSec-SA-2025-2695 | sudo security update | 2025年8月9日 |
产品 | 包 | 状态 |
---|---|---|
V6 | sudo | Fixed |