Bug 1218388 (CVE-2023-7090) - VUL-0: CVE-2023-7090: sudo: Improper handling of ipa_hostname leads to privilege mismanagement
Summary: VUL-0: CVE-2023-7090: sudo: Improper handling of ipa_hostname leads to privil...
Status: RESOLVED DUPLICATE of bug 1181371
Alias: CVE-2023-7090
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/389279/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-7090:7.7:(AV:L...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-12-24 09:43 UTC by SMASH SMASH
Modified: 2024-05-17 08:05 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-12-24 09:43:17 UTC
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-7090
Comment 3 Marcus Meissner 2023-12-24 09:51:45 UTC
Refers to:

GIT repo https://github.com/sudo-project/sudo

commit e99082e05b9f0dd0e0f47fa1d2e1b9d922ea8c4c
Author: Todd C. Miller <Todd.Miller@sudo.ws>
Date:   Thu Aug 15 14:20:12 2019 -0600

    Fix special handling of ipa_hostname that was lost in sudo 1.8.24.
    We now include the long and short hostname in sudo parser container.
Comment 4 Marcus Meissner 2023-12-24 09:54:44 UTC
affects
SUSE:SLE-12-SP5:Update sudo
SUSE:SLE-15:Update sudo

others are newer or older than the affected version 1.8.24->1.8.27.
Comment 5 Otto Hollmann 2024-01-02 12:52:00 UTC
This commit is already present in our codestreams as patch sudo-1.8.27-ipa_hostname.patch
> https://build.suse.de/package/view_file/SUSE:SLE-12-SP5:Update/sudo/sudo-1.8.27-ipa_hostname.patch?expand=1
> https://build.suse.de/package/view_file/SUSE:SLE-15:Update/sudo/sudo-1.8.27-ipa_hostname.patch?expand=1

I suggest to close this bug as duplicate of bug 1181371

Or should I reference this bug and CVE number in changelog anyway?
Comment 6 Otto Hollmann 2024-01-12 10:21:07 UTC
Assigning back to security team (see previous comment)
Comment 7 Andrea Mattiazzo 2024-05-17 08:05:09 UTC
All done, closing.

*** This bug has been marked as a duplicate of bug 1181371 ***