| Thread Tools |
6th February 2020, 14:04 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 153,575
| Sudo has huge bug Su-Sussudio Sudo, a utility found in dozens of Unix-like operating systems, has received a patch for a potentially serious bug that allows unprivileged users to easily obtain unfettered root privileges on vulnerable systems. The vulnerability tracked as CVE-2019-18634, is the result of a stack-based buffer-overflow bug found in versions 1.7.1 through 1.8.25p1. It can be triggered only when either an administrator or a downstream OS, such as Linux Mint and Elementary OS, has enabled an option known as pwfeedback. With pwfeedback turned on, the vulnerability can be exploited even by users who aren't listed in sudoers, a file that contains rules that users must follow when using the sudo command. According to a Sudo advisory exploiting the bug does not require sudo permissions, merely that pwfeedback be enabled. "The bug can be reproduced by passing a large input to Sudo via a pipe when it prompts for a password." The advisory lists two flaws that lead to the vulnerability. The first: pwfeedback isn't ignored as it should be when reading from something other than a terminal. As a result, the saved version of a line erase character remains at its initialized value of 0. The second contributor is that the code that erases the line of asterisks doesn't properly reset the buffer position if there is an error writing data. Instead, the code resets only the remaining buffer length. https://fudzilla.com/news/50255-sudo-has-huge-bug |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
The Moto E4 Plus offers a huge battery without a huge price tag | Stefan Mileschin | WebNews | 0 | 14th June 2017 07:05 |
Linux has had a huge bug for nine years | Stefan Mileschin | WebNews | 0 | 25th October 2016 08:51 |
UK government wants one huge database to help it run the country | Stefan Mileschin | WebNews | 0 | 4th August 2014 17:58 |
Wolfenstein: The New Order Has Huge Day One Patch | Stefan Mileschin | WebNews | 0 | 19th May 2014 09:09 |
HTC One max Review - It's Huge | Stefan Mileschin | WebNews | 0 | 29th October 2013 08:24 |
Huge DoS attack hits China | Stefan Mileschin | WebNews | 0 | 27th August 2013 07:51 |
Huge Giveaway | Sidney | WebNews | 0 | 8th February 2005 04:33 |
Some huge heatsinks :D | 187(V)URD@ | General Madness - System Building Advice | 4 | 11th June 2004 17:19 |
Huge Sale - Various! (oc / ..) | Jada | Mad Bargains | 13 | 30th July 2003 02:49 |
Thread Tools | |
| |