PT-2016-7209 · Red Hat+1 · Red Hat+1
Grisha Levit
·
Published
2016-11-03
·
Updated
2016-12-23
·
CVE-2016-7091
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
sudo (affected versions not specified)
Red Hat Enterprise Linux (affected versions not specified)
Description
A flaw was discovered in the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations, where the value of
INPUTRC is preserved. This could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could exploit this flaw to read content from specially formatted files with elevated privileges provided by sudo.Recommendations
For sudo, consider restricting access to the
INPUTRC variable until a patch is available.
For Red Hat Enterprise Linux, at the moment, there is no information about a newer version that contains a fix for this issue.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Red Hat