Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://www.openwall.com/lists/oss-security/2023/02/28/1 | mailing list exploit third party advisory |
https://www.sudo.ws/releases/stable/#1.9.13p2 | release notes |
http://www.openwall.com/lists/oss-security/2023/03/01/8 | third party advisory mailing list |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLXMRAMXC3BYL4DNKVTK3V6JDMUXZ7B/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6VW24YGXJYI4NZ5HZPQCF4MCE7766AU/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/332KN4QI6QXB7NI7SWSJ2EQJKWIILFN6/ | vendor advisory |
https://security.netapp.com/advisory/ntap-20230413-0009/ | third party advisory |
https://security.gentoo.org/glsa/202309-12 | third party advisory vendor advisory |