CVE-2016-7091
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure.
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges provided by sudo.
- CVSS 3.0
- 4.4 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux hpc node · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/92615Third Party Advisory, VDB Entry
- https://lists.gnu.org/archive/html/bug-readline/2016-05/msg00009.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2593.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/92615Third Party Advisory, VDB Entry
- https://lists.gnu.org/archive/html/bug-readline/2016-05/msg00009.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2016-2593.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.