¡¾Ô´´Â©¶´¡¿sudo rootȨÏÞÈƹý(CVE-2019-14287)
Ðû²¼Ê±¼ä 2019-10-15
1¡¢Åä¾°ÃèÊö
Äþ¾²Ñо¿ÈËÔ±ÔÚsudoÖз¢ÏÖÁËÒ»¸ö©¶´£¬ËüÊÇ×îÖØÒª£¬¹¦Ð§×îÇ¿´óÇÒ×î³£Óõij£Ó÷¨Ê½Ö®Ò»£¬Ëü×÷Ϊ°²×°ÔÚ¼¸ºõËùÓлùÓÚUNIXºÍLinuxµÄ²Ù×÷ϵͳÉϵĺËÐÄÃüÁî¶ø·ºÆð¡£
2¡¢Â©¶´Áбí
©¶´Æ·¼¶£º ÖÐΣ
Ó°Ï췶Χ£º sudo 1.8.28֮ǰµÄ°æ±¾
3¡¢Â©¶´ÏêÇé
¸Ã©¶´ÊÇsudoÄþ¾²¼ÆıÈƹýÎÊÌ⣬¼´Ê¹¡° sudoersÅäÖá±Ã÷È·½ûÖ¹ÁËrootÓû§·ÃÎÊ£¬¸Ã©¶´Ò²¿ÉÄÜÔÊÐí¶ñÒâÓû§»ò·¨Ê½ÒÔrootÓû§Éí·ÝÔÚÄ¿±êLinuxϵͳÉÏÖ´ÐÐÈÎÒâÃüÁî¡£
sudo´ú±í¡°³¬¼¶Óû§¡±£¬ËüÊÇÒ»¸öϵͳÃüÁÔÊÐíÓû§ÒÔÆäËûÓû§µÄÌØȨÔËÐÐÓ¦Ó÷¨Ê½»òÃüÁ¶øÎÞÐèÇл»»·¾³¡£Í¨³£ÒÔrootÓû§Éí·ÝÔËÐÐÃüÁî¡£

Èç¹ûƾ¾Ý³ß¶ÈÅäÖÃϵͳ¼Æı£¬Ôò²»Ò×Êܵ½¹¥»÷¡£Èç¹ûÊǷdz߶ÈÅäÖã¬ÀýÈ磺Runas¹æ·¶Ã÷È·½ûÖ¹root·ÃÎÊ£¬Runas¹æ·¶ÖÐÊ×ÏÈÁгöALLÒªº¦×Ö£¬ÄÇôsudoȨÏÞµÄÓû§¾Í¿ÉÒÔʹÓÃËüÀ´ÒÔrootÉí·ÝÔËÐÐÃüÁî¡£Èç¹ûͨ¹ý-uÑ¡ÏîÖ¸¶¨µÄÓû§IDÔÚÃÜÂëÊý¾Ý¿âÖв»´æÔÚ£¬Òò´Ë²»»áÔËÐÐÈκÎPAM»á»°Ä£¿é¡£


4¡¢ÐÞ¸´½¨Òé
Red Hat Enterprise Linux / CentOS
https://access.redhat.com/security/cve/CVE-2019-14287
Ubuntu
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-14287.html
SUSE / openSUSE
https://www.suse.com/security/cve/CVE-2019-14287.html
5¡¢²Î¿¼Á´½Ó
https://www.sudo.ws/alerts/minus_1_uid.html