NA

CVE-2023-28486

Published: 16/03/2023 Updated: 03/02/2024
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Sudo prior to 1.9.13 does not escape control characters in log messages.

Vulnerable Product Search on Vulmon Subscribe to Product

sudo project sudo

netapp active iq unified manager -

Vendor Advisories

Sudo before 1913 does not escape control characters in log messages (CVE-2023-28486) Sudo before 1913 does not escape control characters in sudoreplay output (CVE-2023-28487) ...
DescriptionThe MITRE CVE dictionary describes this issue as: Sudo before 1913 does not escape control characters in log messages ...