¡¾Ô­´´·ì϶¡¿sudo rootȨÏÞÈÆ¹ý(CVE-2019-14287)

°ä²¼¹¦·ò 2019-10-15

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


1¡¢²¼¾°ÃèÊö


°²È«×êÑÐÈËÔ±ÔÚsudoÖз¢ÏÖÁËÒ»¸ö·ì϶£¬ËüÊÇ×î³ÁÒª£¬Ö°ÄÜ×î׳´óÇÒ×î³£Óõij£Ó÷¨Ê½Ö®Ò»£¬Ëü×÷ΪװÖÃÔÚÏÕЩËùÓлùÓÚUNIXºÍLinuxµÄ²Ù×÷ϵͳÉϵÄÖ÷ÌâºÅÁî¶ø³öÏÖ ¡£


2¡¢·ì϶Áбí


CVE ID  £º   CVE-2019-14287
·ì϶µÈ¼¶£º   ÖÐΣ
Ó°ÏìÁìÓò£º   sudo 1.8.28֮ǰµÄ°æ±¾

3¡¢·ì϶ÏêÇé


¸Ã·ì϶ÊÇsudo°²È«Õ½ÊõÈÆ¹ýÎÊÌ⣬¼´±ã¡° sudoersÅäÖá±Ã÷È·²»ÈÝÁËrootÓû§½Ó¼û£¬¸Ã·ì϶Ҳ¿ÉÄÜÔÊÐí¶ñÒâÓû§»ò·¨Ê½ÒÔrootÓû§Éí·ÝÔÚÖ¸±êLinuxϵͳÉÏÖ´ÐÐËÁÒâºÅÁî ¡£


sudo´ú±í¡°³¬µÈÓû§¡±£¬ËüÊÇÒ»¸öϵͳºÅÁÔÊÐíÓû§ÒÔÆäËûÓû§µÄÌØÈ¨ÔËÐÐÀûÓ÷¨Ê½»òºÅÁ¶øÎÞÐèÇл»»·¾³ ¡£Í¨³£ÒÔrootÓû§Éí·ÝÔËÐкÅÁî ¡£


ĬÈÏÇé¿öÏ£¬ÔÚ´óÎÞÊýLinux¿¯ÐаæÖУ¬ÈçÏÂͼËùʾ£¬/etc/sudoersÎļþÖÐRunAs¹æ·¶ÖеÄALL¹Ø¼ü×ÖÔÊÐíadmin»òsudo×éÖеÄËùÓÐЧ»§ÒÔϵͳÉϵÄÈκÎÓÐЧÓû§Éí·ÝÔËÐÐÈκκÅÁî ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÈôÊÇÒÀÕճ߶ÈÅäÖÃϵͳսÊõ£¬Ôò²»Ò×Êܵ½¹¥»÷ ¡£ÈôÊdz¤¶Ì³ß¶ÈÅäÖã¬ÀýÈ磺Runas¹æ·¼û÷È·²»ÈÝroot½Ó¼û£¬Runas¹æ·¶ÖÐÊ×ÏÈÁгöALL¹Ø¼ü×Ö£¬ÄÇôsudoȨÏÞµÄÓû§¾ÍÄܹ»Ê¹ÓÃËüÀ´ÒÔrootÉí·ÝÔËÐкÅÁî ¡£ÈôÊÇͨ¹ý-uÑ¡ÏîÖ¸¶¨µÄÓû§IDÔÚÃÜÂëÊý¾Ý¿âÖв»´æÔÚ£¬Òò¶ø²»»áÔËÐÐÈκÎPAM»á»°Ä £¿é ¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

4¡¢½¨¸´½¨Òé


Ç¿ÁÒ½¨ÒéÉý¼¶µ½×îа汾£¬¾ßÌåµÄ¿¯Ðа潨Òé²Î¿¼¹ÙÍø¸ø³öµÄ½¨Òé ¡£


Red Hat Enterprise Linux / CentOS
https://access.redhat.com/security/cve/CVE-2019-14287

Ubuntu
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-14287.html

SUSE / openSUSE
https://www.suse.com/security/cve/CVE-2019-14287.html

5¡¢²Î¿¼Á´½Ó


https://thehackernews.com/2019/10/linux-sudo-run-as-root-flaw.html
https://www.sudo.ws/alerts/minus_1_uid.html