ZeroHour

CVE-2016-7091

CVSS 3.0
4.4 medium
EPSS
<1%p34
Published
()
Modified
Description

sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges provided by sudo.

Vendors
redhat
Products
enterprise linux, enterprise linux desktop, enterprise linux hpc node, enterprise linux server, enterprise linux workstation
Weakness
CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.