AIX

 View Only
  • 1.  AIX 7.2.5.3 SUDO-CVE-2023-27320 vulnerability

    Posted Tue March 07, 2023 07:25 AM

    Hello 

    A security vulnerability has been identified with the CVE-2023-27320 code, which causes the system to crash and can be used to gain unauthorized access to the vulnerable system.

    https://www.openwall.com/lists/oss-security/2023/02/28/1

    https://www.sudo.ws/releases/stable/#1.9.13p2

    https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-27320

    I learned that the vulnerability was fixed with the sudo-1.9.13p2 package. where can i download this package

    AIX OS = 7200-05-03-2148

    Thanks



    ------------------------------
    Enis Demir
    ------------------------------


  • 2.  RE: AIX 7.2.5.3 SUDO-CVE-2023-27320 vulnerability

    Posted Tue March 07, 2023 08:00 AM

    Hi Enis Demir,
    Yes CVE-2023-27320  is fixed in  sudo-1.9.13p2, which is not available on AIX tool box now.  We are building sudo-1.9.13p2, Will update you soon.



    ------------------------------
    Sangeetha Bandi
    ------------------------------



  • 3.  RE: AIX 7.2.5.3 SUDO-CVE-2023-27320 vulnerability

    Posted Wed March 08, 2023 01:04 AM

    Hi Sangeetha Bandi,

    Thank you very much for your reply.I'm looking forward to the update

    Thanks



    ------------------------------
    Enis Demir
    ------------------------------



  • 4.  RE: AIX 7.2.5.3 SUDO-CVE-2023-27320 vulnerability

    Posted Fri March 10, 2023 09:25 AM

    Hi  Enis Demir,

    sudo-1.9.13p2 is uploaded to Aix Tool Box. 

    https://public.dhe.ibm.com/aix/freeSoftware/aixtoolbox/SRPMS/sudo
    https://public.dhe.ibm.com/aix/freeSoftware/aixtoolbox/SRPMS/sudo_ids
    https://public.dhe.ibm.com/aix/freeSoftware/aixtoolbox/SRPMS/sudo_noldap



    ------------------------------
    Sangeetha Bandi
    ------------------------------