<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:30:31 +0000</lastBuildDate>
    <item>
      <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/2nga002579</link>
      <description>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/2nga002579</guid>
    </item>
    <item>
      <title>ALSA-2023:0282 — Important: sudo security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:0282</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: sudo, AlmaLinux:9: sudo-python-plugin&lt;/p&gt;
&lt;p&gt;The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sudo: arbitrary file write with privileges of the RunAs user (CVE-2023-22809)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: sudo, AlmaLinux:9: sudo-python-plugin&lt;/p&gt;
&lt;p&gt;The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sudo: arbitrary file write with privileges of the RunAs user (CVE-2023-22809)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:0282</guid>
    </item>
    <item>
      <title>bdu:2023-00210</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-00210</link>
      <description>bdu:2023-00210</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-00210</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2023-22809 — CVE-2023-22809 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-22809</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-22809</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0043 — Une vulnérabilité a été découverte dans sudo. Elle permet à un attaquant
de provoquer un contournement de la politique…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0043</link>
      <description>certfr-2023-avi-0043</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0043</guid>
    </item>
    <item>
      <title>EUVD-2026-227133</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-227133</link>
      <description>EUVD-2026-227133</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-227133</guid>
    </item>
    <item>
      <title>fkie_cve-2023-22809</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-22809</link>
      <description>&lt;p&gt;In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a &amp;#34;--&amp;#34; argument that defeats a protection mechanism, e.g., an EDITOR=&amp;#39;vim -- /path/to/extra/file&amp;#39; value.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a &amp;#34;--&amp;#34; argument that defeats a protection mechanism, e.g., an EDITOR=&amp;#39;vim -- /path/to/extra/file&amp;#39; value.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-22809</guid>
    </item>
    <item>
      <title>GHSA-3vwp-294x-6v9c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3vwp-294x-6v9c</link>
      <description>&lt;p&gt;In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a &amp;#34;--&amp;#34; argument that defeats a protection mechanism, e.g., an EDITOR=&amp;#39;vim -- /path/to/extra/file&amp;#39; value.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a &amp;#34;--&amp;#34; argument that defeats a protection mechanism, e.g., an EDITOR=&amp;#39;vim -- /path/to/extra/file&amp;#39; value.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3vwp-294x-6v9c</guid>
    </item>
    <item>
      <title>gsd-2023-22809</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-22809</link>
      <description>gsd-2023-22809</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-22809</guid>
    </item>
    <item>
      <title>ICSA-25-105-08 — ABB M2M Gateway</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-105-08</link>
      <description>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-105-08</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-22809 — In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environme…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-22809</link>
      <description>msrc_CVE-2023-22809</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-22809</guid>
    </item>
    <item>
      <title>OESA-2023-1049 — sudo security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1049</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: sudo, openEuler:20.03-LTS-SP3: sudo, openEuler:22.03-LTS: sudo, openEuler:22.03-LTS-SP1: sudo&lt;/p&gt;
&lt;p&gt;Sudo is a program designed to allow a sysadmin to give limited root privileges to users and log root activity.  The basic philosophy is to give as few privileges as possible but still allow people to get their work done.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a &amp;amp;quot;--&amp;amp;quot; argument that defeats a protection mechanism, e.g., an EDITOR=&amp;amp;apos;vim -- /path/to/extra/file&amp;amp;apos; value.(CVE-2023-22809)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: sudo, openEuler:20.03-LTS-SP3: sudo, openEuler:22.03-LTS: sudo, openEuler:22.03-LTS-SP1: sudo&lt;/p&gt;
&lt;p&gt;Sudo is a program designed to allow a sysadmin to give limited root privileges to users and log root activity.  The basic philosophy is to give as few privileges as possible but still allow people to get their work done.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a &amp;amp;quot;--&amp;amp;quot; argument that defeats a protection mechanism, e.g., an EDITOR=&amp;amp;apos;vim -- /path/to/extra/file&amp;amp;apos; value.(CVE-2023-22809)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1049</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12638-1 — sudo-1.9.12p2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12638-1</link>
      <description>&lt;p&gt;sudo-1.9.12p2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sudo-1.9.12p2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12638-1</guid>
    </item>
    <item>
      <title>RHSA-2023:0280 — Red Hat Security Advisory: sudo security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:0280</link>
      <description>&lt;p&gt;sudo: arbitrary file write with privileges of the RunAs user&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sudo: arbitrary file write with privileges of the RunAs user&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:0280</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:0100-1 — Security update for sudo</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:0100-1</link>
      <description>&lt;p&gt;Security update for sudo&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for sudo&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:0100-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-22809</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-22809</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: sudo, Ubuntu:Pro:16.04:LTS: sudo, Ubuntu:18.04:LTS: sudo, Ubuntu:20.04:LTS: sudo, Ubuntu:22.04:LTS: sudo&lt;/p&gt;
&lt;p&gt;In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a &amp;#34;--&amp;#34; argument that defeats a protection mechanism, e.g., an EDITOR=&amp;#39;vim -- /path/to/extra/file&amp;#39; value.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: sudo, Ubuntu:Pro:16.04:LTS: sudo, Ubuntu:18.04:LTS: sudo, Ubuntu:20.04:LTS: sudo, Ubuntu:22.04:LTS: sudo&lt;/p&gt;
&lt;p&gt;In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a &amp;#34;--&amp;#34; argument that defeats a protection mechanism, e.g., an EDITOR=&amp;#39;vim -- /path/to/extra/file&amp;#39; value.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-22809</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0151 — sudo: Schwachstelle ermöglicht Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0151</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in sudo ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in sudo ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0151</guid>
    </item>
  </channel>
</rss>
