<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:21:13.097627+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:0811</id>
    <title>ALSA-2024:0811 — Moderate: sudo security update</title>
    <updated>2026-10-02T14:21:13.400971+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: sudo, AlmaLinux:9: sudo-python-plugin</p>
<p>The sudo packages contain the sudo utility which allows system
administrators to provide certain users with the permission to execute
privileged commands, which are used for system management purposes, without
having to log in as root.</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* CVE-2023-28487 sudo: Sudo does not escape control characters in sudoreplay output
* CVE-2023-28486 sudo: Sudo does not escape control characters in log messages
* CVE-2023-42465 sudo: Targeted Corruption of Register and Stack Variables</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:0811"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03866</id>
    <title>bdu:2023-03866</title>
    <updated>2026-10-02T14:21:13.401034+00:00</updated>
    <content>bdu:2023-03866</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03866"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-28486</id>
    <title>BELL-CVE-2023-28486</title>
    <updated>2026-10-02T14:21:13.401052+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: sudo</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-28486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0119</id>
    <title>certfr-2024-avi-0119 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Siemens&lt;/span&gt;. Certaines d'entr…</title>
    <updated>2026-10-02T14:21:13.401069+00:00</updated>
    <content>certfr-2024-avi-0119</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0119"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-8365</id>
    <title>EUVD-2026-8365</title>
    <updated>2026-10-02T14:21:13.401085+00:00</updated>
    <content>EUVD-2026-8365</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-8365"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-28486</id>
    <title>fkie_cve-2023-28486</title>
    <updated>2026-10-02T14:21:13.401096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sudo before 1.9.13 does not escape control characters in log messages.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-28486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pr34-r4f9-f5c6</id>
    <title>GHSA-pr34-r4f9-f5c6</title>
    <updated>2026-10-02T14:21:13.401116+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sudo before 1.9.13 does not escape control characters in log messages.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pr34-r4f9-f5c6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-28486</id>
    <title>gsd-2023-28486</title>
    <updated>2026-10-02T14:21:13.401129+00:00</updated>
    <content>gsd-2023-28486</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-28486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-046-11</id>
    <title>ICSA-24-046-11 — Siemens SCALANCE XCM-/XRM-300</title>
    <updated>2026-10-02T14:21:13.401139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.</p>
<p>This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-046-11"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-28486</id>
    <title>msrc_CVE-2023-28486 — Sudo before 1.9.13 does not escape control characters in log messages.</title>
    <updated>2026-10-02T14:21:13.401589+00:00</updated>
    <content>msrc_CVE-2023-28486</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-28486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1205</id>
    <title>OESA-2023-1205 — sudo security update</title>
    <updated>2026-10-02T14:21:13.401607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: sudo, openEuler:20.03-LTS-SP3: sudo, openEuler:22.03-LTS: sudo, openEuler:22.03-LTS-SP1: sudo</p>
<p>Sudo is a program designed to allow a sysadmin to give limited root privileges to users and log root activity.  The basic philosophy is to give as few privileges as possible but still allow people to get their work done.

Security Fix(es):

Sudo before 1.9.13 does not escape control characters in sudoreplay output.(CVE-2023-28487)

Sudo before 1.9.13 does not escape control characters in log messages.(CVE-2023-28486)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1205"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0811</id>
    <title>RHSA-2024:0811 — Red Hat Security Advisory: sudo security update</title>
    <updated>2026-10-02T14:21:13.401634+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sudo: Sudo does not escape control characters in log messages sudo: Sudo does not escape control characters in sudoreplay output sudo: Targeted Corruption of Register and Stack Variables</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0811"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1383</id>
    <title>RHSA-2024:1383 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.15.0 security, enhancement, &amp; bug fix update</title>
    <updated>2026-10-02T14:21:13.401654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rpm: TOCTOU race in checks for unsafe symlinks rpm: races with chown/chmod/capabilities calls during installation rpm: checks for unsafe symlinks are not performed for intermediary directories Hashicorp/vault: Vault’s LDAP Auth Method Allows for User Enumeration openssl: Incorrect cipher key and IV length processing vault: inbound client requests can trigger a denial of service gnutls: timing side-channel in the RSA-PSK authentication sqlite: heap-buffer-overflow at sessionfuzz golang: crypto/internal/nistec: specific unreduced P-256 scalars produce incorrect results follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple sudo: Sudo does not escape control characters in log messages sudo: Sudo does not escape control characters in sudoreplay output golang: net/http: insufficient sanitization of Host header golang: crypto/tls: slow verification of certificate chains containing large RSA keys golang: html/template: improper handling of HTML-like comments within script contexts golang: html/template: improper handling of special tags within script contexts golang: crypto/tls: panic when processing post-handshake message on QUIC connections golang: crypto/tls: lack of a limit on buffered post-handshake libxml2: crafted xml can cause global buffer overflow nodejs-ip: arbitrary code execution via the isPublic() function sudo: Targeted Cor…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:1659-1</id>
    <title>SUSE-SU-2023:1659-1 — Security update for sudo</title>
    <updated>2026-10-02T14:21:13.401725+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for sudo</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:1659-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28486</id>
    <title>UBUNTU-CVE-2023-28486</title>
    <updated>2026-10-02T14:21:13.401742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: sudo, Ubuntu:Pro:16.04:LTS: sudo, Ubuntu:18.04:LTS: sudo, Ubuntu:20.04:LTS: sudo, Ubuntu:22.04:LTS: sudo</p>
<p>Sudo before 1.9.13 does not escape control characters in log messages.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0667</id>
    <title>WID-SEC-W-2023-0667 — sudo: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-02T14:21:13.401766+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in sudo ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0667"/>
  </entry>
</feed>
