CVE-2023-22809: Buffer Overflow
A vulnerability was found in sudo. Exposure in how sudoedit handles user-provided environment variables leads to arbitrary file writing with privileges of the RunAs user (usually root). The prerequisite for exploitation is that the current user must be authorized by the sudoers policy to edit a file using sudoedit.
Other sources
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Accessibility. This issue was addressed with improved checks.
— Apple
Accounts. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
AMD. A buffer overflow issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. This issue was addressed by forcing hardened runtime on the affected binaries at the system level.
— Apple
Credit
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-32388
- CVE-2023-32400
- CVE-2023-34352
- CVE-2023-32379
- CVE-2023-32411
- CVE-2023-32383
- CVE-2023-32371
- CVE-2023-32386
- CVE-2023-32399
- CVE-2023-28191
- CVE-2023-32360
- CVE-2023-32387
- CVE-2023-32414
- CVE-2023-32417
- CVE-2023-32392
- CVE-2023-32372
- CVE-2023-32384
- CVE-2023-32410
- CVE-2023-32420
- CVE-2023-27930
- CVE-2023-27940
- CVE-2023-32398
- CVE-2023-32413
- CVE-2023-32352
- CVE-2023-29469
- CVE-2023-42869
- CVE-2023-32369
- CVE-2023-32405
- CVE-2023-32428
- CVE-2023-32407
- CVE-2023-42958
- CVE-2023-32368
- CVE-2023-32375
- CVE-2023-32382
- CVE-2023-32380
- CVE-2023-32403
- CVE-2023-32437
- CVE-2023-32355
- CVE-2023-32385
- CVE-2023-32395
- CVE-2023-32390
- CVE-2023-32401
- CVE-2023-32357
- CVE-2023-32363
- CVE-2023-32367
- CVE-2023-32432
- CVE-2023-32397
- CVE-2023-32391
- CVE-2023-32404
- CVE-2023-32394
- CVE-2023-32422
- CVE-2023-32376
- CVE-2023-22809
- CVE-2023-28202
- CVE-2023-32412
- CVE-2023-32408
- CVE-2023-32415
- CVE-2023-32402
- CVE-2023-32423
- CVE-2023-32409
- CVE-2023-28204
- CVE-2023-32373
- CVE-2023-32389
Frequently Asked Questions
What is CVE-2023-22809?
CVE-2023-22809 is a vulnerability in the sudo package that allows a local attacker to escalate privileges by appending arbitrary entries to the list of files to process.
How severe is CVE-2023-22809?
CVE-2023-22809 is considered to be a high severity vulnerability with a severity value of 7.
How does CVE-2023-22809 affect sudo?
CVE-2023-22809 affects sudo versions before 1.9.12p2.
How can I fix CVE-2023-22809?
To fix CVE-2023-22809, update sudo to version 1.9.12p2 or later.
Where can I find more information about CVE-2023-22809?
You can find more information about CVE-2023-22809 at the following sources: - [CVE Website](https://www.cve.org/CVERecord?id=CVE-2023-22809) - [NVD Website](https://nvd.nist.gov/vuln/detail/CVE-2023-22809) - [Sudo GitHub](https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_12p2) - [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2161142) - [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2023:0287)