PT-2016-7209 · Red Hat+1 · Red Hat+1

Grisha Levit

·

Published

2016-11-03

·

Updated

2016-12-23

·

CVE-2016-7091

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions sudo (affected versions not specified) Red Hat Enterprise Linux (affected versions not specified)
Description A flaw was discovered in the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations, where the value of INPUTRC is preserved. This could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could exploit this flaw to read content from specially formatted files with elevated privileges provided by sudo.
Recommendations For sudo, consider restricting access to the INPUTRC variable until a patch is available. For Red Hat Enterprise Linux, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2016_2593
CVE-2016-7091
RHSA-2016:2593
RHSA-2016_2593

Affected Products

Centos
Red Hat