<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:31:03.907981+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/2nga002579</id>
    <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
    <updated>2026-10-02T20:31:03.958898+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/2nga002579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:0282</id>
    <title>ALSA-2023:0282 — Important: sudo security update</title>
    <updated>2026-10-02T20:31:03.959020+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: sudo, AlmaLinux:9: sudo-python-plugin</p>
<p>The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root.</p>
<p>Security Fix(es):</p>
<p>* sudo: arbitrary file write with privileges of the RunAs user (CVE-2023-22809)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:0282"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-00210</id>
    <title>bdu:2023-00210</title>
    <updated>2026-10-02T20:31:03.959075+00:00</updated>
    <content>bdu:2023-00210</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-00210"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-22809</id>
    <title>Withdrawn: BELL-CVE-2023-22809 — CVE-2023-22809 does not affect BellSoft software</title>
    <updated>2026-10-02T20:31:03.959097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-22809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0043</id>
    <title>certfr-2023-avi-0043 — Une vulnérabilité a été découverte dans sudo. Elle permet à un attaquant
de provoquer un contournement de la politique…</title>
    <updated>2026-10-02T20:31:03.959119+00:00</updated>
    <content>certfr-2023-avi-0043</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-227133</id>
    <title>EUVD-2026-227133</title>
    <updated>2026-10-02T20:31:03.959142+00:00</updated>
    <content>EUVD-2026-227133</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-227133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-22809</id>
    <title>fkie_cve-2023-22809</title>
    <updated>2026-10-02T20:31:03.959158+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-22809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3vwp-294x-6v9c</id>
    <title>GHSA-3vwp-294x-6v9c</title>
    <updated>2026-10-02T20:31:03.959195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3vwp-294x-6v9c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-22809</id>
    <title>gsd-2023-22809</title>
    <updated>2026-10-02T20:31:03.959234+00:00</updated>
    <content>gsd-2023-22809</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-22809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-105-08</id>
    <title>ICSA-25-105-08 — ABB M2M Gateway</title>
    <updated>2026-10-02T20:31:03.959285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-105-08"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-22809</id>
    <title>msrc_CVE-2023-22809 — In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environme…</title>
    <updated>2026-10-02T20:31:03.959343+00:00</updated>
    <content>msrc_CVE-2023-22809</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-22809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1049</id>
    <title>OESA-2023-1049 — sudo security update</title>
    <updated>2026-10-02T20:31:03.959370+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: sudo, openEuler:20.03-LTS-SP3: sudo, openEuler:22.03-LTS: sudo, openEuler:22.03-LTS-SP1: sudo</p>
<p>Sudo is a program designed to allow a sysadmin to give limited root privileges to users and log root activity.  The basic philosophy is to give as few privileges as possible but still allow people to get their work done.

Security Fix(es):

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a &amp;quot;--&amp;quot; argument that defeats a protection mechanism, e.g., an EDITOR=&amp;apos;vim -- /path/to/extra/file&amp;apos; value.(CVE-2023-22809)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12638-1</id>
    <title>openSUSE-SU-2024:12638-1 — sudo-1.9.12p2-1.1 on GA media</title>
    <updated>2026-10-02T20:31:03.959416+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sudo-1.9.12p2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12638-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:0280</id>
    <title>RHSA-2023:0280 — Red Hat Security Advisory: sudo security update</title>
    <updated>2026-10-02T20:31:03.959443+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sudo: arbitrary file write with privileges of the RunAs user</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:0280"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:0100-1</id>
    <title>SUSE-SU-2023:0100-1 — Security update for sudo</title>
    <updated>2026-10-02T20:31:03.959466+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for sudo</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:0100-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-22809</id>
    <title>UBUNTU-CVE-2023-22809</title>
    <updated>2026-10-02T20:31:03.959489+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: sudo, Ubuntu:Pro:16.04:LTS: sudo, Ubuntu:18.04:LTS: sudo, Ubuntu:20.04:LTS: sudo, Ubuntu:22.04:LTS: sudo</p>
<p>In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-22809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0151</id>
    <title>WID-SEC-W-2023-0151 — sudo: Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-02T20:31:03.959533+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in sudo ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0151"/>
  </entry>
</feed>
