Computer Security
[EN] securityvulns.ru
no-pyccku



sudo protection bypass
updated since 01.03.2010
Published:22.04.2010
Source:BUGTRAQ
SecurityVulns ID:10655
Type:local
Level:6/10
Description:when a pseudocommand is enabled, it's possible to created an executable file with the same name, it will be executed by relative name with escalated privileges.
CVE:CVE-2010-1163 (The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.)
 CVE-2010-0426 (sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.)
Original documentdocumentAgazzini Maurizio, sudoedit local privilege escalation through PATH manipulation (22.04.2010)
 documentUBUNTU, [USN-928-1] Sudo vulnerability (19.04.2010)
 documentKingcope Kingcope, Todd Miller Sudo local root exploit discovered by Slouching (02.03.2010)
 documentMANDRIVA, [ MDVSA-2010:049 ] sudo (01.03.2010)
Files:Tod Miller Sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4
Discuss:Read or add your comments to this news (2 comments)

  Дмитрий_123: Обход защиты в sudo  02.03.2010 2:58:17
 Дык это же старая дырка... и только сейчас ее запихнули в официальные уязвимости?
   3APA3A: Re: Обход защиты в sudo  02.03.2010 21:52:00
  Когда-то, например, межсайтовый скриптинг не считался уязвимостью. Aleph1 в принципе в бугтрак сообщения о межсайтовом скриптинге не пропускал. Стандарты меняются.

Show Threads
Messages
 
Login:* (Register)
Password:*
(private) To:
(reply) Subject:*
Text:

Main Forum (Eng)

General security questions not appropriate for another forums.
3proxy Forum (Eng)

All 3proxy question must be posted to this forum.
Bugs, Vulnerabilities, PoCs and Exploits (Eng)

All vulnerability related questions, vulnerability digging and exploit creation.
Windows programming and administration (Eng)

Administering Windows and application development.
Unix programming and administation (Eng)

Administering Unix and application development.
Test forum

Please post all test messages here. All test messages from different forums will be deteted.
Main Forum (Rus)
3proxy Forum (Rus)
Bugs, Vulnerabilities, PoCs and Exploits (Rus)
Windows programming and administration (Rus)
Unix programming and administation (Rus)
About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru