{"id":38918,"date":"2019-10-31T22:26:45","date_gmt":"2019-10-31T19:26:45","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil\/"},"modified":"2019-10-31T22:26:45","modified_gmt":"2019-10-31T19:26:45","slug":"uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil","title":{"rendered":"Vulnerabilit\u00e0 in sudo che consente l'elevazione dei privilegi utilizzando regole specifiche","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nell'utility <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sudo.ws\/\">Sudo<\/a><\/noindex>, utilizzata per gestire l'esecuzione di comandi per conto di altri utenti, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/14\/1\">identificata<\/a><\/noindex>  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sudo.ws\/alerts\/minus_1_uid.html\">vulnerabilit\u00e0<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-14287\">CVE-2019-14287<\/a><\/noindex>), che consente di eseguire comandi con diritti di root, a condizione che nelle impostazioni sudoers ci siano regole in cui, nella sezione di verifica dell'identificatore utente, dopo la parola chiave autorizzativa \u00abALL\u00bb ci sia un divieto esplicito di avviare con diritti di root (\u00ab\u2026 (ALL, !root) \u2026\u00bb). Nelle configurazioni predefinite delle distribuzioni, la vulnerabilit\u00e0 non si manifesta. <\/p>\n<p>Nel caso in cui nelle sudoers ci siano regole valide, ma estremamente rare nella pratica, che consentono l'esecuzione di un determinato comando sotto un identificatore UID di qualsiasi utente, tranne root, un attaccante che ha i permessi per eseguire tale comando pu\u00f2 aggirare la limitazione stabilita ed eseguire il comando con diritti di root. Per aggirare la limitazione \u00e8 sufficiente tentare di eseguire il comando indicato nelle impostazioni con UID \u00ab-1\u00bb o \u00ab4294967295\u00bb, il che porter\u00e0 alla sua esecuzione con UID 0.  <\/p>\n<p>Ad esempio, se nelle impostazioni c'\u00e8 una regola che consente a qualsiasi utente di eseguire il programma \/usr\/bin\/id con qualsiasi UID:<\/p>\n<p>   myhost ALL = (ALL, !root) \/usr\/bin\/id<\/p>\n<p>o una variante che consente l'esecuzione solo all'utente specifico bob:<\/p>\n<p>   myhost bob = (ALL, !root) \/usr\/bin\/id<\/p>\n<p>L'utente pu\u00f2 eseguire \u00absudo -u \u2018#-1\u2019 id\u00bb e l'utilit\u00e0 \/usr\/bin\/id verr\u00e0 avviata con diritti di root, nonostante un divieto esplicito nelle impostazioni. Il problema \u00e8 causato dall'aver trascurato i valori speciali \u00ab-1\u00bb o \u00ab4294967295\u00bb, che non portano a un cambio di UID, ma poich\u00e9 sudo stesso \u00e8 gi\u00e0 eseguito come root, sia il UID che il comando target vengono eseguiti anch'essi con diritti di root. <\/p>\n<p>Nelle distribuzioni SUSE e openSUSE, senza specificare nella regola \u00abNOPASSWD\u00bb, la vulnerabilit\u00e0 <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2019-14287\">non \u00e8 sfruttabile<\/a><\/noindex>, poich\u00e9 nelle sudoers \u00e8 abilitato per impostazione predefinita il modo \u00abDefaults targetpw\u00bb, in cui viene effettuato un controllo UID contro il database delle password con la richiesta di inserire la password dell'utente target. Per tali sistemi, l'attacco pu\u00f2 essere portato a termine solo se ci sono regole del tipo:<\/p>\n<p>   myhost ALL = (ALL, !root) NOPASSWD:  \/usr\/bin\/id<\/p>\n<p>Il problema \u00e8 stato risolto nella versione <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sudo.ws\/sudo\/news.html\">Sudo 1.8.28<\/a><\/noindex>. La correzione \u00e8 disponibile anche sotto forma di <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sudo.ws\/repos\/sudo\/rev\/83db8dba09e7\">patch<\/a><\/noindex>. Nelle distribuzioni la vulnerabilit\u00e0 \u00e8 gi\u00e0 stata risolta in <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-14287\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.archlinux.org\/packages\/core\/x86_64\/sudo\/\">Arch Linux<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2019-14287\">SUSE\/openSUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-14287.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugs.gentoo.org\/show_bug.cgi?id=CVE-2019-14287\">Gentoo<\/a><\/noindex> e <noindex><a rel=\"nofollow\" href=\"https:\/\/www.freshports.org\/security\/sudo\/\">FreeBSD<\/a><\/noindex>. Al momento della scrittura dell'articolo, il problema rimane non risolto in <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-14287\">RHEL<\/a><\/noindex> e <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F30&#038;type=security\">Fedora<\/a><\/noindex>. La vulnerabilit\u00e0 \u00e8 stata identificata dai ricercatori di sicurezza della Apple.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51675\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 Sudo, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-14287), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u043f\u0440\u0438 \u043d\u0430\u043b\u0438\u0447\u0438\u0438 \u0432 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u0445 sudoers \u043f\u0440\u0430\u0432\u0438\u043b, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0432 \u0441\u0435\u043a\u0446\u0438\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u043f\u043e\u0441\u043b\u0435 \u0440\u0430\u0437\u0440\u0435\u0448\u0430\u044e\u0449\u0435\u0433\u043e \u043a\u043b\u044e\u0447\u0435\u0432\u043e\u0433\u043e \u0441\u043b\u043e\u0432\u0430 &#171;ALL&#187; \u0441\u043b\u0435\u0434\u0443\u0435\u0442 \u044f\u0432\u043d\u044b\u0439 \u0437\u0430\u043f\u0440\u0435\u0442 \u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root (&#171;&#8230; (ALL, !root) &#8230;&#187;). \u0412 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 \u043f\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38918","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 Sudo, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 sudo, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u0430\u0432\u0438\u043b | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 Sudo, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:26:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:26:45+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 in sudo che consente di elevare i privilegi utilizzando regole specifiche | ProHoster","description":"Nell'utility Sudo, utilizzata per eseguire comandi a nome di altri utenti,","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 sudo, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u0430\u0432\u0438\u043b | ProHoster","og:description":"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 Sudo, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439,","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-sudo-pozvolyayushhaya-povysit-privilegii-pri-ispolzovanii-spetsifichnyh-pravil","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:26:45+00:00","article:modified_time":"2019-10-31T19:26:45+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38918","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 23:57:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:00:27","updated":"2026-01-23 23:57:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/38918","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=38918"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/38918\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=38918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=38918"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=38918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}