ื ืงื•ื“ืช ืชื•ืจืคื” ื‘-sudo ื”ืžืืคืฉืจืช ืœืฉื ื•ืช ื›ืœ ืงื•ื‘ืฅ ื‘ืžืขืจื›ืช

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช (CVE-2023-22809) ื‘ื—ื‘ื™ืœืช sudo, ื”ืžืฉืžืฉืช ืœืืจื’ื•ืŸ ื‘ื™ืฆื•ืข ืคืงื•ื“ื•ืช ืžื˜ืขื ืžืฉืชืžืฉื™ื ืื—ืจื™ื, ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœืขืจื•ืš ื›ืœ ืงื•ื‘ืฅ ื‘ืžืขืจื›ืช, ืžื” ืฉื‘ืชื•ืจื•, ืžืืคืฉืจ ืœื”ื ืœื”ืฉื™ื’ ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ ืขืœ ื™ื“ื™ ืฉื™ื ื•ื™ /etc/shadow ืื• ืกืงืจื™ืคื˜ื™ื ืฉืœ ืžืขืจื›ืช. ื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช ืžื—ื™ื™ื‘ ืฉื”ืžืฉืชืžืฉ ื‘ืงื•ื‘ืฅ sudoers ื™ืงื‘ืœ ืืช ื”ื–ื›ื•ืช ืœื”ืคืขื™ืœ ืืช ืชื•ื›ื ื™ืช ื”ืฉื™ืจื•ืช sudoedit ืื• "sudo" ืขื ื”ื“ื’ืœ "-e".

ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืžื”ื™ืขื“ืจ ื˜ื™ืคื•ืœ ื ื›ื•ืŸ ื‘ืชื•ื•ื™ "-" ื‘ืขืช ื ื™ืชื•ื— ืžืฉืชื ื™ ืกื‘ื™ื‘ื” ื”ืžื’ื“ื™ืจื™ื ืืช ื”ืชื•ื›ื ื™ืช ืฉื ืงืจืืช ืœืขืจื•ืš ืงื•ื‘ืฅ. ื‘-sudo, ื”ืจืฆืฃ "-" ืžืฉืžืฉ ืœื”ืคืจื“ืช ื”ืขื•ืจืš ื•ื”ืืจื’ื•ืžื ื˜ื™ื ืžืจืฉื™ืžืช ื”ืงื‘ืฆื™ื ื”ื ืขืจื›ื™ื. ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ื•ืกื™ืฃ ืืช ื”ืจืฆืฃ "-file" ืœืื—ืจ ื ืชื™ื‘ ื”ืขื•ืจืš ืœืžืฉืชื ื™ ื”ืกื‘ื™ื‘ื” SUDO_EDITOR, VISUAL ืื• EDITOR, ืืฉืจ ื™ืชื—ื™ืœ ืขืจื™ื›ื” ืฉืœ ื”ืงื•ื‘ืฅ ืฉืฆื•ื™ืŸ ืขื ื”ืจืฉืื•ืช ื’ื‘ื•ื”ื•ืช ืžื‘ืœื™ ืœื‘ื“ื•ืง ืืช ื›ืœืœื™ ื”ื’ื™ืฉื” ืœืงื•ื‘ืฅ ืฉืœ ื”ืžืฉืชืžืฉ.

ื”ืคื’ื™ืขื•ืช ืžื•ืคื™ืขื” ืžืื– ืกื ื™ืฃ 1.8.0 ื•ืชื•ืงื ื” ื‘ืขื“ื›ื•ืŸ ื”ืžืชืงืŸ sudo 1.9.12p2. ื ื™ืชืŸ ืœืขืงื•ื‘ ืื—ืจ ืคืจืกื•ื ืขื“ื›ื•ื ื™ ื”ื—ื‘ื™ืœื•ืช ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ื: Debian, Ubuntu, Gentoo, RHEL, SUSE, Fedora, Arch, FreeBSD, NetBSD. ื›ืคืชืจื•ืŸ ืื‘ื˜ื—ื”, ืืชื” ื™ื›ื•ืœ ืœื”ืฉื‘ื™ืช ืืช ื”ืขื™ื‘ื•ื“ ืฉืœ ืžืฉืชื ื™ ื”ืกื‘ื™ื‘ื” SUDO_EDITOR, VISUAL ื•-EDITOR ืขืœ ื™ื“ื™ ืฆื™ื•ืŸ ื‘-sudoers: Defaults!sudoedit env_delete+="SUDO_EDITOR VISUAL EDITOR"

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”