git: 04e87de39e3c - main - security/vuxml: sudo<1.9.17p1 privilege escalation

From: Matthias Andree <mandree_at_FreeBSD.org>
Date: Tue, 01 Jul 2025 17:45:53 UTC
The branch main has been updated by mandree:

URL: https://cgit.FreeBSD.org/ports/commit/?id=04e87de39e3c82255c25019cbba3c43d8a21362a

commit 04e87de39e3c82255c25019cbba3c43d8a21362a
Author:     Matthias Andree <mandree@FreeBSD.org>
AuthorDate: 2025-07-01 17:44:25 +0000
Commit:     Matthias Andree <mandree@FreeBSD.org>
CommitDate: 2025-07-01 17:45:51 +0000

    security/vuxml: sudo<1.9.17p1 privilege escalation
    
    PR:             287938
    Security:       24f4b495-56a1-11f0-9621-93abbef07693
    Security:       CVE-2025-32462
    Security:       CVE-2025-32463
---
 security/vuxml/vuln/2025.xml | 50 ++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 50 insertions(+)

diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml
index 0070df448a11..29b966ccfd90 100644
--- a/security/vuxml/vuln/2025.xml
+++ b/security/vuxml/vuln/2025.xml
@@ -1,3 +1,53 @@
+  <vuln vid="24f4b495-56a1-11f0-9621-93abbef07693">
+    <topic>sudo -- privilege escalation vulnerability through host and chroot options</topic>
+    <affects>
+      <package>
+	<name>sudo</name>
+	<range><lt>1.9.17p1</lt></range>
+      </package>
+      <package>
+	<name>sudo-sssd</name>
+	<range><lt>1.9.17p1</lt></range>
+      </package>
+    </affects>
+    <description>
+	<body xmlns="http://www.w3.org/1999/xhtml">
+	<p>Todd C. Miller reports, crediting Rich Mirch from Stratascale Cyber Research Unit (CRU):</p>
+	<blockquote cite="https://www.sudo.ws/releases/stable/">
+	  <p>Sudo 1.9.17p1:</p>
+	  <ul>
+	    <li>
+	      Fixed CVE-2025-32462. Sudo's -h (--host) option could be specified
+	      when running a command or editing a file. This could enable a
+	      local privilege escalation attack if the sudoers file allows the
+	      user to run commands on a different host. For more information,
+	      see Local Privilege Escalation via host option.
+	    </li>
+	    <li>
+	      Fixed CVE-2025-32463. An attacker can leverage sudo's -R
+	      (--chroot) option to run arbitrary commands as root, even if they
+	      are not listed in the sudoers file. The chroot support has been
+	      deprecated an will be removed entirely in a future release. For
+	      more information, see Local Privilege Escalation via chroot
+	      option.
+	    </li>
+	  </ul>
+	</blockquote>
+	</body>
+    </description>
+    <references>
+      <cvename>CVE-2025-32462</cvename>
+      <cvename>CVE-2025-32463</cvename>
+      <url>https://www.sudo.ws/releases/stable/</url>
+      <url>https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-host</url>
+      <url>https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot</url>
+    </references>
+    <dates>
+      <discovery>2025-04-01</discovery>
+      <entry>2025-07-01</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="8df49466-5664-11f0-943a-18c04d5ea3dc">
     <topic>xorg server -- Multiple vulnerabilities</topic>
     <affects>