HomeSecurityOld Ubuntu bug allows access to sudo

Old Ubuntu bug allows sudo access

Ubuntu

In September 2013, a bug was reported to Canonical by user Mark Smith, which existed in various versions of Ubuntu, and which could allow malicious users to exploit sudo and gain access to user accounts, even without knowing the corresponding passwords.

Since then, several users have reported that the bug can affect various managers, such as Unity, KDE, GNOME and Cinnamon, and as has been documented, it can also affect OS X for MAC computers.

The bug appears to be based on the fact that many users change the system clock, disabling synchronization with the Internet. One could also use the command “cat /var/log/auth.log”, to find the last time the user entered their sudo credentials.

While the bug report was previously kept confidential due to the sensitive data it contained, the Ubuntu team has now decided to release the report publicly, without the approval of the person who discovered it, Mark Smith. This decision appears to have been made in order to get a fixas quickly as possible to fix the problem.

A few hours after the post about the bug in a Reddit thread, it was confirmed that the problem exists in Ubuntu versions 12.04 LTS (Precise Pangolin), 14.04 LTS (Trusty Tahr), 14.10 (Utopic Unicorn), and finally 15.04 (Vivid Vervet).

It is not yet known how serious this bug is, as it has not been given a severity rating yet. Users are reporting that Canonical will soon release a fix to fix the problem.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS