¡¾Ô´´·ì϶¡¿sudo rootȨÏÞÈÆ¹ý(CVE-2019-14287)
°ä²¼¹¦·ò 2019-10-15

1¡¢¡¢¡¢²¼¾°ÃèÊö
°²È«×êÑÐÈËÔ±ÔÚsudoÖз¢ÏÖÁËÒ»¸ö·ì϶£¬£¬£¬ËüÊÇ×îÖØÒª£¬£¬£¬Ö°ÄÜ×î׳´óÇÒ×î³£Óõij£Ó÷¨Ê½Ö®Ò»£¬£¬£¬Ëü×÷ΪװÖÃÔÚÏÕЩËùÓлùÓÚUNIXºÍLinuxµÄ²Ù×÷ϵͳÉϵÄÖ÷ÌâºÅÁî¶ø³öÏÖ¡£¡£¡£
2¡¢¡¢¡¢·ì϶Áбí
·ì϶µÈ¼¶£º£º£º ÖÐΣ
Ó°ÏìÁìÓò£º£º£º sudo 1.8.28֮ǰµÄ°æ±¾
3¡¢¡¢¡¢·ì϶ÏêÇé
¸Ã·ì϶ÊÇsudo°²È«Õ½ÊõÈÆ¹ýÎÊÌ⣬£¬£¬¼´±ã¡° sudoersÅäÖá±Ã÷È·²»ÈÝÁËrootÓû§½Ó¼û£¬£¬£¬¸Ã·ì϶Ҳ¿ÉÄÜÔÊÐí¶ñÒâÓû§»ò·¨Ê½ÒÔrootÓû§Éí·ÝÔÚÖ¸±êLinuxϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£
sudo´ú±í¡°³¬µÈÓû§¡±£¬£¬£¬ËüÊÇÒ»¸öϵͳºÅÁ£¬£¬ÔÊÐíÓû§ÒÔÆäËûÓû§µÄÌØÈ¨ÔËÐÐÀûÓ÷¨Ê½»òºÅÁ£¬£¬¶øÎÞÐèÇл»»·¾³¡£¡£¡£Í¨³£ÒÔrootÓû§Éí·ÝÔËÐкÅÁî¡£¡£¡£
ÈôÊÇÒÀÕճ߶ÈÅäÖÃϵͳսÊõ£¬£¬£¬Ôò²»Ò×Êܵ½¹¥»÷¡£¡£¡£ÈôÊdz¤¶Ì³ß¶ÈÅäÖ㬣¬£¬ÀýÈ磺£º£ºRunas¹æ·¶Ã÷È·²»ÈÝroot½Ó¼û£¬£¬£¬Runas¹æ·¶ÖÐÊ×ÏÈÁгöALL¹Ø¼ü×Ö£¬£¬£¬ÄÇôsudoȨÏÞµÄÓû§¾ÍÄܹ»Ê¹ÓÃËüÀ´ÒÔrootÉí·ÝÔËÐкÅÁî¡£¡£¡£ÈôÊÇͨ¹ý-uÑ¡ÏîÖ¸¶¨µÄÓû§IDÔÚÃÜÂëÊý¾Ý¿âÖв»´æÔÚ£¬£¬£¬Òò¶ø²»»áÔËÐÐÈκÎPAM»á»°Ä£¿£¿é¡£¡£¡£
4¡¢¡¢¡¢ÐÞ¸´½¨Òé
Red Hat Enterprise Linux / CentOS
https://access.redhat.com/security/cve/CVE-2019-14287
Ubuntu
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-14287.html
SUSE / openSUSE
https://www.suse.com/security/cve/CVE-2019-14287.html
5¡¢¡¢¡¢²Î¿¼Á´½Ó
https://www.sudo.ws/alerts/minus_1_uid.html


¾©¹«Íø°²±¸11010802024551ºÅ