• Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
Tutorial News Comments FAQ Related Articles

UNIX and Linux with Glaring Sudo EnableFlaw Malicious Users to Run Arbitrary Commands

{{postValue.id}}

Sudo is a core command that is installed with all the UNIX and Linux based operating system and it is one of the most commonly used Linux commands. Sudo is a powerful utility that allows the user to access the commands and applications of other users without switching the environment. Superuser do is shortly known as the Sudo.

Joe Vennix of Apple Information Security discovered that Sudo deals with some bypass flaw which means that Sudo has a flaw in security because it allows the user to execute the commands and applications just with the user ID "-1" or "4294967295" as the password. But Sudo carries an inbuilt function that considers the general user ID as 0 which is the user ID for the root user. This is the major reason behind the bypass flaw in Sudo.

The possibility of being attacked in Sudo is tracked as CVE-2019-14287. The only way to exploit the security flaw in Sudo is to specify the user Id this can resolve the issue in the conversation function. This bypass flaw is found in all the versions of Sudo except in the latest Sudo version 1.8.28.

Tags:
jacob
Author: 

Comments ( 0 )

No comments available

Add a comment
{{postCtrl.cmtErrMsg}}

Frequently asked questions ( 0 )

No questions available

Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Luk Van De Looverbosch ?
How to create a root ?

Hello,
How to create root@linuxhelp in Linux Mint 20.1 64-bit ?
Thanks in advance for your reply.
Best regards.

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.