HomeSecurityNew sudo command bug puts Linux users at risk

New sudo command bug puts Linux users at risk

A vulnerability has recently been discovered in the Linux sudo (super user do) command. This could allow users who do not have privileges to execute commands as root. The good news is that not all Linux servers, as it is a type of vulnerability that only affects atypical configurations.

sudo

But first, let's look at how the sudo command works and how it can be configured. When executing commands on a Linux operating system , unprivileged users can use the sudo command to execute commands as root. The main requirement is that they have been granted permission or know the root password

The sudo command can be configured to allow a user to run commands as another user by adding special instructions to the configuration file. The following commands allow the user `test` to run the commands /usr/bin/vim and /usr/bin/id as any user except root.

When a user is created in Linux, they are given a UID. Users can use these UIDs instead of a username when launching the sudo command.

Now let's get back to the vulnerability in question . Apple security researcher Joe Vennix discovered a bug that allows users to launch a sudo command as root using the “-1” or “4294967295” UID. For example, the following command could use this bug to launch the user /usr/bin/id as root, even though the user `test' denied it in the /etc/sudoers file.

The truth is that this is a powerful error, but it is important to know that it can only work if a user has access to a command via the sudoers file. Otherwise this error will have no effect.

sudo

For a vulnerability to be exploitable, a user must have a sudoer directive configured for a commandthat can launch other commands.

While this bug is obviously powerful, it can still only be exploited under atypical configurations that won't affect the vast majority of Linux users.

Users using directives are advised to upgrade to sudo 1.8.28 or later as soon as possible.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS