¡¾Îó²îͨ¸æ¡¿CVE-2019-18634 | sudoȨÏÞÌáÉýÎó²î

Ðû²¼Ê±¼ä 2020-02-04

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Åä¾°ÐÎò


Çå¾²Ñо¿Ö°Ô±·¢Ã÷sudo³ÌÐò±£´æÒ»¸öÎó²î £¬£¬£¬£¬ÔÚÌØ¶¨ÉèÖÃÏ¿ÉÄÜÔÊÐíµÍÌØÈ¨Óû§»ò¶ñÒâ³ÌÐòÔÚLinux»òmacOSϵͳÉÏÒÔrootÉí·ÝÖ´ÐÐí§ÒâÏÂÁî ¡£¡£¡£


Ó°Ïì¹æÄ£


CVE ID  £º   CVE-2019-18634


Ó°Ïì¹æÄ££º   sudo 1.8.26֮ǰµÄ°æ±¾£¨ËäÈ»ÔÚsudo°æ±¾1.8.26ÖÁ1.8.30ÖÐÒ²±£´æ¸ÃÎó²î £¬£¬£¬£¬µ«ÓÉÓÚsudo 1.8.26ÖÐÒýÈëµÄEOF´¦Öóͷ£·½·¨µÄת±ä £¬£¬£¬£¬¸ÃÎó²îÎÞ·¨±»Ê¹Óã©


Îó²îÏêÇé


ÔÚ1.8.26֮ǰµÄsudoÖÐ £¬£¬£¬£¬ÈôÊÇÔÚ/etc/sudoersÖÐÆôÓÃÁËpwfeedback £¬£¬£¬£¬ÔòÓû§¿ÉÒÔÔÚÌØÈ¨sudoÀú³ÌÖд¥·¢»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³ö ¡£¡£¡£¹¥»÷ÕßÐèÒª½«³¤×Ö·û¹´×ª´ï¸øtgetpass.cÖеÄgetln() ¡£¡£¡£


Ö»ÓÐÔÚsudoersÉèÖÃÎļþÖÐÆôÓÃÁË¡° pwfeedback¡±Ñ¡Ïîʱ £¬£¬£¬£¬²Å»ªÊ¹ÓøÃÎó²î ¡£¡£¡£µ±Óû§ÔÚÖÕ¶ËÖÐÊäÈëÃÜÂëʱ £¬£¬£¬£¬¸ÃÑ¡Ïî»áÌṩÊÓ¾õ·´Ïì £¬£¬£¬£¬¼´ÏÔʾÐǺţ¨*£© ¡£¡£¡£ÐèÒª×¢ÖØµÄÊÇ £¬£¬£¬£¬ÔÚsudoµÄÉÏÓΰ汾»òÐí¶àÆäËüÈí¼þ°üÖÐ £¬£¬£¬£¬Ä¬ÈÏÇéÐÎÏÂδÆôÓÃpwfeedback¹¦Ð§ ¡£¡£¡£¿ÉÊÇ £¬£¬£¬£¬Ä³Ð©Linux¿¯Ðа棨ÀýÈçLinux MintºÍElementary OS£©ÔÚÆäĬÈÏsudoersÎļþÖÐÆôÓÃÁ˸ù¦Ð§ ¡£¡£¡£


³ý´ËÖ®Íâ £¬£¬£¬£¬ÆôÓÃpwfeedbackʱ £¬£¬£¬£¬×ÝȻûÓÐsudoȨÏÞ £¬£¬£¬£¬ÈκÎÓû§¶¼¿ÉÒÔʹÓôËÎó²î ¡£¡£¡£


ÐÞ¸´½¨Òé


¸üÐÂÖÁsudo°æ±¾1.8.31 ¡£¡£¡£


²Î¿¼Á´½Ó


https://nvd.nist.gov/vuln/detail/CVE-2019-18634

https://thehackernews.com/2020/02/sudo-linux-vulnerability.html

https://securityaffairs.co/wordpress/97265/breaking-news/sudo-cve-2019-18634-flaw.html