{"id":38918,"date":"2019-10-31T22:26:45","date_gmt":"2019-10-31T19:26:45","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil\/"},"modified":"2019-10-31T22:26:45","modified_gmt":"2019-10-31T19:26:45","slug":"uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil","title":{"rendered":"Sicherheitsanf\u00e4lligkeit in Sudo, die eine Erh\u00f6hung der Berechtigungen durch spezifische Regeln erm\u00f6glicht","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In der Dienstprogramm <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sudo.ws\/\">Sudo<\/a><\/noindex>, das zur Ausf\u00fchrung von Befehlen im Namen anderer Benutzer verwendet wird, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/14\/1\">wurde<\/a><\/noindex>  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sudo.ws\/alerts\/minus_1_uid.html\">in Cisco-Switches die gesamte Unternehmensnetzwerkwelt fast weltweit in Frage.<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-14287\">CVE-2019-14287<\/a><\/noindex>), die es erlaubt, Befehle mit root-Rechten auszuf\u00fchren, sofern in den sudoers-Einstellungen Regeln festgelegt sind, in denen in der \u00dcberpr\u00fcfung des Benutzer-IDs nach dem erlaubenden Schl\u00fcsselwort \u201eALL\u201c ein ausdr\u00fcckliches Verbot zum Starten mit root-Rechten folgt (\u201a\u2026 (ALL, !root) \u2026\u2018). In den Standardkonfigurationen der Distributionen tritt die Schwachstelle nicht auf. <\/p>\n<p>Bei Vorhandensein von erlaubten, aber in der Praxis \u00e4u\u00dferst seltenen Regeln in sudoers, die das Ausf\u00fchren eines bestimmten Befehls unter der UID-Identifikation eines beliebigen Benutzers au\u00dfer root erlauben, kann ein Angreifer, der berechtigt ist, diesen Befehl auszuf\u00fchren, die festgelegte Einschr\u00e4nkung umgehen und den Befehl mit root-Rechten ausf\u00fchren. Um die Einschr\u00e4nkung zu umgehen, gen\u00fcgt es, zu versuchen, den in den Einstellungen angegebenen Befehl mit der UID \u201a-1\u2018 oder \u201a4294967295\u2018 auszuf\u00fchren, was zur Ausf\u00fchrung mit der UID 0 f\u00fchrt.  <\/p>\n<p>Wenn beispielsweise in den Einstellungen eine Regel vorhanden ist, die jedem Benutzer das Recht gibt, das Programm \/usr\/bin\/id unter beliebiger UID auszuf\u00fchren:<\/p>\n<p>   myhost ALL = (ALL, !root) \/usr\/bin\/id<\/p>\n<p>oder eine Variante, die die Ausf\u00fchrung nur f\u00fcr den bestimmten Benutzer bob erlaubt:<\/p>\n<p>   myhost bob = (ALL, !root) \/usr\/bin\/id<\/p>\n<p>Der Benutzer kann \u201asudo -u \u2018#-1\u2019 id\u2018 ausf\u00fchren, und das Tool \/usr\/bin\/id wird mit root-Rechten gestartet, obwohl dies in den Einstellungen ausdr\u00fccklich verboten ist. Das Problem resultiert aus der Vernachl\u00e4ssigung der Sonderwerte \u201a-1\u2018 oder \u201a4294967295\u2018, die nicht zu einer UID-\u00c4nderung f\u00fchren, aber da sudo bereits unter root ausgef\u00fchrt wird, wird auch der Zielbefehl ohne UID-\u00c4nderung mit root-Rechten gestartet. <\/p>\n<p>In den Distributionen SUSE und openSUSE tritt die Schwachstelle ohne die Angabe der Regel \u201aNOPASSWD\u2018 auf. <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2019-14287\">nicht ausnutzbar<\/a><\/noindex>, da im sudoers standardm\u00e4\u00dfig der Modus \u201aDefaults targetpw\u2018 aktiviert ist, bei dem die UID anhand der Passwortdatenbank \u00fcberpr\u00fcft wird und eine Eingabeaufforderung f\u00fcr das Passwort des Zielbenutzers angezeigt wird. F\u00fcr solche Systeme kann der Angriff nur unter Vorhandensein von Regeln der Art erfolgen:<\/p>\n<p>   myhost ALL = (ALL, !root) NOPASSWD: \/usr\/bin\/id<\/p>\n<p>Das Problem wurde in der Version <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sudo.ws\/sudo\/news.html\">Sudo 1.8.28<\/a><\/noindex>behoben. Der Fix ist auch in Form von <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sudo.ws\/repos\/sudo\/rev\/83db8dba09e7\">Patch<\/a><\/noindex>verf\u00fcgbar. In den Distributionen wurde die Verwundbarkeit bereits in <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-14287\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.archlinux.org\/packages\/core\/x86_64\/sudo\/\">Arch Linux<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2019-14287\">SUSE\/openSUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-14287.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugs.gentoo.org\/show_bug.cgi?id=CVE-2019-14287\">Gentoo<\/a><\/noindex> und <noindex><a rel=\"nofollow\" href=\"https:\/\/www.freshports.org\/security\/sudo\/\">FreeBSD<\/a><\/noindex>behoben. Zum Zeitpunkt der Ver\u00f6ffentlichung dieser Nachricht bleibt das Problem jedoch in <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-14287\">RHEL<\/a><\/noindex> und <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F30&#038;type=security\">, aber bisher ist er noch nicht in<\/a><\/noindex>unbehebbar. Die Sicherheitsanf\u00e4lligkeit wurde von Sicherheitsexperten von Apple entdeckt.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51675\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 Sudo, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-14287), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u043f\u0440\u0438 \u043d\u0430\u043b\u0438\u0447\u0438\u0438 \u0432 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u0445 sudoers \u043f\u0440\u0430\u0432\u0438\u043b, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0432 \u0441\u0435\u043a\u0446\u0438\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u043f\u043e\u0441\u043b\u0435 \u0440\u0430\u0437\u0440\u0435\u0448\u0430\u044e\u0449\u0435\u0433\u043e \u043a\u043b\u044e\u0447\u0435\u0432\u043e\u0433\u043e \u0441\u043b\u043e\u0432\u0430 &#171;ALL&#187; \u0441\u043b\u0435\u0434\u0443\u0435\u0442 \u044f\u0432\u043d\u044b\u0439 \u0437\u0430\u043f\u0440\u0435\u0442 \u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root (&#171;&#8230; (ALL, !root) &#8230;&#187;). \u0412 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 \u043f\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38918","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 Sudo, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 sudo, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u0430\u0432\u0438\u043b | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 Sudo, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:26:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:26:45+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Schwachstelle in Sudo, die eine Privilegienerh\u00f6hung bei spezifischen Regeln erm\u00f6glicht | ProHoster","description":"Im Sudo-Dienstprogramm, das verwendet wird, um Befehle im Namen anderer Benutzer auszuf\u00fchren,","canonical_url":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 sudo, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u0430\u0432\u0438\u043b | ProHoster","og:description":"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 Sudo, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439,","og:url":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:26:45+00:00","article:modified_time":"2019-10-31T19:26:45+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38918","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 23:57:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:00:27","updated":"2026-01-23 23:57:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/38918","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=38918"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/38918\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=38918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=38918"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=38918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}