• CVE-2025-32463

发布时间: 2025年7月4日

修改时间: 2025年7月11日

概要

A vulnerability has been found in Todd Miller sudo 1.9.14/1.9.15/1.9.16/1.9.17 (Operating System Utility Software) and classified as critical.The manipulation of the argument -R/--chroot with an unknown input leads to a unknown weakness. The CWE definition for the vulnerability is CWE-284. The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.As an impact it is known to affect confidentiality, integrity, and availability.Applying the patch 1.9.17p1 is able to eliminate this problem.

CVSS v3 指标

NVD openEuler
Confidentiality High High
Attack Vector Local Local
CVSS评分 7.8 9.3
Attack Complexity Low Low
Privileges Required Low None
Scope Unchanged Changed
Integrity High High
User Interaction None None
Availability High High

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2579 sudo security update 2025年7月3日
KylinSec-SA-2025-2695 sudo security update 2025年8月9日

影响产品

产品 状态
V6 sudo Fixed