CVE-2023-27320
moderate-risk
Published 2023-02-28
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Do I need to act?
-
0.21% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.2/10
High
NETWORK
/ LOW complexity
Affected Vendors
References (16)
Third Party Advisory
https://security.gentoo.org/glsa/202309-12
Third Party Advisory
https://security.netapp.com/advisory/ntap-20230413-0009/
Release Notes
https://www.sudo.ws/releases/stable/#1.9.13p2
Third Party Advisory
https://security.gentoo.org/glsa/202309-12
Third Party Advisory
https://security.netapp.com/advisory/ntap-20230413-0009/
Release Notes
https://www.sudo.ws/releases/stable/#1.9.13p2
40
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
1/34 · Minimal
Exposure
13/34 · Low