¡¾Îó²îͨ¸æ¡¿CVE-2019-18634 | sudoȨÏÞÌáÉýÎó²î
Ðû²¼Ê±¼ä 2020-02-04

Åä¾°ÐÎò
Çå¾²Ñо¿Ö°Ô±·¢Ã÷sudo³ÌÐò±£´æÒ»¸öÎó²î£¬£¬£¬£¬ÔÚÌØ¶¨ÉèÖÃÏ¿ÉÄÜÔÊÐíµÍÌØÈ¨Óû§»ò¶ñÒâ³ÌÐòÔÚLinux»òmacOSϵͳÉÏÒÔrootÉí·ÝÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£
Ó°Ïì¹æÄ£
CVE ID £º CVE-2019-18634
Ó°Ïì¹æÄ££º sudo 1.8.26֮ǰµÄ°æ±¾£¨ËäÈ»ÔÚsudo°æ±¾1.8.26ÖÁ1.8.30ÖÐÒ²±£´æ¸ÃÎó²î£¬£¬£¬£¬µ«ÓÉÓÚsudo 1.8.26ÖÐÒýÈëµÄEOF´¦Öóͷ£·½·¨µÄת±ä£¬£¬£¬£¬¸ÃÎó²îÎÞ·¨±»Ê¹Óã©
Îó²îÏêÇé
ÔÚ1.8.26֮ǰµÄsudoÖУ¬£¬£¬£¬ÈôÊÇÔÚ/etc/sudoersÖÐÆôÓÃÁËpwfeedback£¬£¬£¬£¬ÔòÓû§¿ÉÒÔÔÚÌØÈ¨sudoÀú³ÌÖд¥·¢»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³ö¡£¡£¡£¡£¹¥»÷ÕßÐèÒª½«³¤×Ö·û¹´×ª´ï¸øtgetpass.cÖеÄgetln()¡£¡£¡£¡£
Ö»ÓÐÔÚsudoersÉèÖÃÎļþÖÐÆôÓÃÁË¡° pwfeedback¡±Ñ¡Ïîʱ£¬£¬£¬£¬²Å»ªÊ¹ÓøÃÎó²î¡£¡£¡£¡£µ±Óû§ÔÚÖÕ¶ËÖÐÊäÈëÃÜÂëʱ£¬£¬£¬£¬¸ÃÑ¡Ïî»áÌṩÊÓ¾õ·´Ï죬£¬£¬£¬¼´ÏÔʾÐǺţ¨*£©¡£¡£¡£¡£ÐèÒª×¢ÖØµÄÊÇ£¬£¬£¬£¬ÔÚsudoµÄÉÏÓΰ汾»òÐí¶àÆäËüÈí¼þ°üÖУ¬£¬£¬£¬Ä¬ÈÏÇéÐÎÏÂδÆôÓÃpwfeedback¹¦Ð§¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬Ä³Ð©Linux¿¯Ðа棨ÀýÈçLinux MintºÍElementary OS£©ÔÚÆäĬÈÏsudoersÎļþÖÐÆôÓÃÁ˸ù¦Ð§¡£¡£¡£¡£
³ý´ËÖ®Í⣬£¬£¬£¬ÆôÓÃpwfeedbackʱ£¬£¬£¬£¬×ÝȻûÓÐsudoȨÏÞ£¬£¬£¬£¬ÈκÎÓû§¶¼¿ÉÒÔʹÓôËÎó²î¡£¡£¡£¡£
ÐÞ¸´½¨Òé
¸üÐÂÖÁsudo°æ±¾1.8.31¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2019-18634
https://thehackernews.com/2020/02/sudo-linux-vulnerability.html
https://securityaffairs.co/wordpress/97265/breaking-news/sudo-cve-2019-18634-flaw.html


¾©¹«Íø°²±¸11010802024551ºÅ