It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Sudo has huge bug Sudo has huge bug
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Sudo has huge bug
Reply
 
Thread Tools
Old 6th February 2020, 13:04   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 149,092
Stefan Mileschin Freshly Registered
Default Sudo has huge bug

Su-Sussudio

Sudo, a utility found in dozens of Unix-like operating systems, has received a patch for a potentially serious bug that allows unprivileged users to easily obtain unfettered root privileges on vulnerable systems.

The vulnerability tracked as CVE-2019-18634, is the result of a stack-based buffer-overflow bug found in versions 1.7.1 through 1.8.25p1. It can be triggered only when either an administrator or a downstream OS, such as Linux Mint and Elementary OS, has enabled an option known as pwfeedback. With pwfeedback turned on, the vulnerability can be exploited even by users who aren't listed in sudoers, a file that contains rules that users must follow when using the sudo command.

According to a Sudo advisory exploiting the bug does not require sudo permissions, merely that pwfeedback be enabled.

"The bug can be reproduced by passing a large input to Sudo via a pipe when it prompts for a password."

The advisory lists two flaws that lead to the vulnerability. The first: pwfeedback isn't ignored as it should be when reading from something other than a terminal. As a result, the saved version of a line erase character remains at its initialized value of 0. The second contributor is that the code that erases the line of asterisks doesn't properly reset the buffer position if there is an error writing data. Instead, the code resets only the remaining buffer length.

https://fudzilla.com/news/50255-sudo-has-huge-bug
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
The Moto E4 Plus offers a huge battery without a huge price tag Stefan Mileschin WebNews 0 14th June 2017 06:05
Linux has had a huge bug for nine years Stefan Mileschin WebNews 0 25th October 2016 07:51
UK government wants one huge database to help it run the country Stefan Mileschin WebNews 0 4th August 2014 16:58
Wolfenstein: The New Order Has Huge Day One Patch Stefan Mileschin WebNews 0 19th May 2014 08:09
HTC One max Review - It's Huge Stefan Mileschin WebNews 0 29th October 2013 07:24
Huge DoS attack hits China Stefan Mileschin WebNews 0 27th August 2013 06:51
Huge Giveaway Sidney WebNews 0 8th February 2005 03:33
Some huge heatsinks :D 187(V)URD@ General Madness - System Building Advice 4 11th June 2004 16:19
Huge Sale - Various! (oc / ..) Jada Mad Bargains 13 30th July 2003 01:49

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 08:10.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO