¡¾Ô­´´Â©¶´¡¿sudo rootȨÏÞÈÆ¹ý(CVE-2019-14287)

Ðû²¼Ê±¼ä 2019-10-15

×ðÁú¶¶È¦ - Ϊdu¶øÉú


1¡¢Åä¾°ÃèÊö


Äþ¾²Ñо¿ÈËÔ±ÔÚsudoÖз¢ÏÖÁËÒ»¸ö©¶´ £¬ËüÊÇ×îÖØÒª £¬¹¦Ð§×îÇ¿´óÇÒ×î³£Óõij£Ó÷¨Ê½Ö®Ò» £¬Ëü×÷Ϊ°²×°ÔÚ¼¸ºõËùÓлùÓÚUNIXºÍLinuxµÄ²Ù×÷ϵͳÉϵĺËÐÄÃüÁî¶ø·ºÆð ¡£


2¡¢Â©¶´Áбí


CVE ID  £º   CVE-2019-14287
©¶´Æ·¼¶£º   ÖÐΣ
Ó°Ï췶Χ£º   sudo 1.8.28֮ǰµÄ°æ±¾

3¡¢Â©¶´ÏêÇé


¸Ã©¶´ÊÇsudoÄþ¾²¼ÆÄ±ÈƹýÎÊÌâ £¬¼´Ê¹¡° sudoersÅäÖá±Ã÷È·½ûÖ¹ÁËrootÓû§·ÃÎÊ £¬¸Ã©¶´Ò²¿ÉÄÜÔÊÐí¶ñÒâÓû§»ò·¨Ê½ÒÔrootÓû§Éí·ÝÔÚÄ¿±êLinuxϵͳÉÏÖ´ÐÐÈÎÒâÃüÁî ¡£


sudo´ú±í¡°³¬¼¶Óû§¡± £¬ËüÊÇÒ»¸öϵͳÃüÁî £¬ÔÊÐíÓû§ÒÔÆäËûÓû§µÄÌØÈ¨ÔËÐÐÓ¦Ó÷¨Ê½»òÃüÁî £¬¶øÎÞÐèÇл»»·¾³ ¡£Í¨³£ÒÔrootÓû§Éí·ÝÔËÐÐÃüÁî ¡£


ĬÈÏÇé¿öÏ £¬ÔÚ´ó¶àÊýLinux¿¯ÐаæÖÐ £¬ÈçÏÂͼËùʾ £¬/etc/sudoersÎļþÖÐRunAs¹æ·¶ÖеÄALLÒªº¦×ÖÔÊÐíadmin»òsudo×éÖеÄËùÓÐÓû§ÒÔϵͳÉϵÄÈκÎÓÐЧÓû§Éí·ÝÔËÐÐÈκÎÃüÁî ¡£

×ðÁú¶¶È¦ - Ϊdu¶øÉú

Èç¹ûƾ¾Ý³ß¶ÈÅäÖÃϵͳ¼ÆÄ± £¬Ôò²»Ò×Êܵ½¹¥»÷ ¡£Èç¹ûÊǷdz߶ÈÅäÖà £¬ÀýÈ磺Runas¹æ·¶Ã÷È·½ûÖ¹root·ÃÎÊ £¬Runas¹æ·¶ÖÐÊ×ÏÈÁгöALLÒªº¦×Ö £¬ÄÇôsudoȨÏÞµÄÓû§¾Í¿ÉÒÔʹÓÃËüÀ´ÒÔrootÉí·ÝÔËÐÐÃüÁî ¡£Èç¹ûͨ¹ý-uÑ¡ÏîÖ¸¶¨µÄÓû§IDÔÚÃÜÂëÊý¾Ý¿âÖв»´æÔÚ £¬Òò´Ë²»»áÔËÐÐÈκÎPAM»á»°Ä £¿é ¡£

×ðÁú¶¶È¦ - Ϊdu¶øÉú

×ðÁú¶¶È¦ - Ϊdu¶øÉú

4¡¢ÐÞ¸´½¨Òé


Ç¿ÁÒ½¨ÒéÉý¼¶µ½×îа汾 £¬¾ßÌåµÄ¿¯Ðа潨Òé²Î¿¼¹ÙÍø¸ø³öµÄ½¨Òé ¡£


Red Hat Enterprise Linux / CentOS
https://access.redhat.com/security/cve/CVE-2019-14287

Ubuntu
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-14287.html

SUSE / openSUSE
https://www.suse.com/security/cve/CVE-2019-14287.html

5¡¢²Î¿¼Á´½Ó


https://thehackernews.com/2019/10/linux-sudo-run-as-root-flaw.html
https://www.sudo.ws/alerts/minus_1_uid.html