ALT-PU-2019-2943-1
Closed vulnerabilities
Published: 2019-10-14
BDU:2019-03696
Уязвимость программы системного администрирования Sudo, существующая из-за недостаточной проверки входных данных, выполнить произвольные команды с привилегиями root
Severity: HIGH (7.8)
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2019-10-17
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-14287
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
Severity: HIGH (8.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References:
- openSUSE-SU-2019:2316
- openSUSE-SU-2019:2316
- openSUSE-SU-2019:2333
- openSUSE-SU-2019:2333
- http://packetstormsecurity.com/files/154853/Slackware-Security-Advisory-sudo-Updates.html
- http://packetstormsecurity.com/files/154853/Slackware-Security-Advisory-sudo-Updates.html
- [oss-security] 20191014 Sudo: CVE-2019-14287
- [oss-security] 20191014 Sudo: CVE-2019-14287
- [oss-security] 20191023 Membership application for linux-distros - VMware
- [oss-security] 20191023 Membership application for linux-distros - VMware
- [oss-security] 20191029 Re: Membership application for linux-distros - VMware
- [oss-security] 20191029 Re: Membership application for linux-distros - VMware
- [oss-security] 20210914 Re: Oracle Solaris membership in the distros list
- [oss-security] 20210914 Re: Oracle Solaris membership in the distros list
- RHBA-2019:3248
- RHBA-2019:3248
- RHSA-2019:3197
- RHSA-2019:3197
- RHSA-2019:3204
- RHSA-2019:3204
- RHSA-2019:3205
- RHSA-2019:3205
- RHSA-2019:3209
- RHSA-2019:3209
- RHSA-2019:3219
- RHSA-2019:3219
- RHSA-2019:3278
- RHSA-2019:3278
- RHSA-2019:3694
- RHSA-2019:3694
- RHSA-2019:3754
- RHSA-2019:3754
- RHSA-2019:3755
- RHSA-2019:3755
- RHSA-2019:3895
- RHSA-2019:3895
- RHSA-2019:3916
- RHSA-2019:3916
- RHSA-2019:3941
- RHSA-2019:3941
- RHSA-2019:4191
- RHSA-2019:4191
- RHSA-2020:0388
- RHSA-2020:0388
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1964-1] sudo security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1964-1] sudo security update
- FEDORA-2019-9cb221f2be
- FEDORA-2019-9cb221f2be
- FEDORA-2019-72755db9c7
- FEDORA-2019-72755db9c7
- FEDORA-2019-67998e9f7e
- FEDORA-2019-67998e9f7e
- https://resources.whitesourcesoftware.com/blog-whitesource/new-vulnerability-in-sudo-cve-2019-14287
- https://resources.whitesourcesoftware.com/blog-whitesource/new-vulnerability-in-sudo-cve-2019-14287
- 20191015 [slackware-security] sudo (SSA:2019-287-01)
- 20191015 [slackware-security] sudo (SSA:2019-287-01)
- 20191015 [SECURITY] [DSA 4543-1] sudo security update
- 20191015 [SECURITY] [DSA 4543-1] sudo security update
- GLSA-202003-12
- GLSA-202003-12
- https://security.netapp.com/advisory/ntap-20191017-0003/
- https://security.netapp.com/advisory/ntap-20191017-0003/
- https://support.f5.com/csp/article/K53746212?utm_source=f5support&%3Butm_medium=RSS
- https://support.f5.com/csp/article/K53746212?utm_source=f5support&%3Butm_medium=RSS
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03976en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03976en_us
- USN-4154-1
- USN-4154-1
- DSA-4543
- DSA-4543
- [oss-security] 20191015 Re: Sudo: CVE-2019-14287
- [oss-security] 20191015 Re: Sudo: CVE-2019-14287
- https://www.sudo.ws/alerts/minus_1_uid.html
- https://www.sudo.ws/alerts/minus_1_uid.html
Closed bugs
CVE-2019-14287 в sudo < 1.8.28