Junglewise Threat Intelligence

CVE-2023-42456: Trifecta Tech Foundation sudo-rs path traversal in session file handling

CVE-2023-42456 · Severity: low · CVSS 3.3 · Published 2023-09-21

Technologies: Trifecta Tech Foundation Sudo-Rs. Vendors: crates.io.

Executive brief

sudo-rs is a memory-safe implementation of the sudo utility used to manage administrative permissions on Linux systems. A vulnerability was found where a user with a specially crafted username containing path characters (like dots and slashes) could trick the system into deleting or corrupting arbitrary files. This could allow an attacker to disable critical system tools or cause a service outage, though it requires the ability to create or log in as a user with an unusual name.

Technical details

A path traversal vulnerability exists in sudo-rs versions 0.2.0 and earlier due to improper neutralization of usernames when constructing session file paths in /var/run/sudo-rs/ts. If an attacker can authenticate as a user with a name containing traversal sequences (e.g., '../../../../bin/cp'), executing 'sudo -K' causes the application to resolve the session file path to an unintended location and attempt to clear it. This results in the corruption or effective removal of the target file. The vulnerability is exploitable on systems like Debian Bookworm or Ubuntu 24.04 that do not strictly validate username characters during account creation. The issue is resolved in version 0.2.1 by using UIDs instead of usernames for session filenames.

Affected products

  • Trifecta Tech Foundation sudo-rs <= 0.2.0

Timeline

  • 2023-09-21: advisory
  • 2023-09-21: disclosed
  • 2023-09-21: patched: Fixed in version 0.2.1
  • 2026-06-10: other: Advisory updated to reflect lower severity based on username creation restrictions.

References

Related threats