PT-2019-4664 · Todd Miller+4 · Sudo+4
CVE-2019-19232
·
Publicado
2019-12-19
·
Atualizado
2024-08-05
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Sudo versions 1.8.29 and earlier
Description
The issue is related to the sudoer account with Runas ALL privileges, allowing an attacker to impersonate a nonexistent user by invoking sudo with a numeric uid not associated with any user. This behavior was considered an intentional feature by the software maintainer, but it surprised some users. As a result, sudo 1.8.30 introduced an option to enable or disable this behavior, with the default being disabled.
Recommendations
For Sudo versions 1.8.29 and earlier, consider updating to version 1.8.30 or later, which introduces an option to enable or disable the behavior of running commands via sudo as a user not present in the local password database. As a temporary workaround, restrict access to the Runas ALL sudoer account to minimize the risk of exploitation.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Astra Linux
Centos
Red Hat
Sudo