Re: Flaw In Sudo Enables Non-Privileged Users To Run Commands As Root

Lawrence D'Oliveiro <[email protected]> Tue, 15 Oct 2019 15:23:19 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Organization Geek Central
Message-ID <[email protected]>
On Tue, 15 Oct 2019 13:32:26 +1300, Peter Reutemann quoted:

> 'The vulnerability in question is a sudo security policy bypass
> issue that could allow a malicious user or a program to execute
> arbitrary commands as root on a targeted Linux system even when the
> "sudoers configuration" explicitly disallows the root access.'

Which, it should be pointed out, is a rather unusual way to use sudo.
More commonly it is used to allow selected non-root users to run things
as root.

More details here
<https://www.theregister.co.uk/2019/10/14/linux_sudo_security_bug/>.
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz