Instructions to address sudo vulnerability
search cancel

Instructions to address sudo vulnerability

book

Article ID: 371324

calendar_today

Updated On:

Products

VMware Integrated OpenStack

Issue/Introduction

A security scan against the management plane vm's returns this CVE:

  • CVE-2021-3156

Environment

7.3

Cause

Photon has issued a security Advisory, PHSA-2021-3.0-0188

Resolution

The issue with bindutils is addressed with sudo-1.9.5-2.

  1. Determine version of package that is installed
    rpm -qa sudo


  2. If the package version returned is less than sudo-1.9.5-2:
    tdnf update sudo