{"id":55921,"date":"2020-02-01T00:00:00","date_gmt":"2020-01-31T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/root-uyazvimost-v-sudo-zatragivayushhaya-linux-mint-i-elementary-os"},"modified":"2020-02-18T14:04:05","modified_gmt":"2020-02-18T11:04:05","slug":"root-uyazvimost-v-sudo-zatragivayushhaya-linux-mint-i-elementary-os","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/root-uyazvimost-v-sudo-zatragivayushhaya-linux-mint-i-elementary-os","title":{"rendered":"Vulnerabilitate root \u00een sudo, afect\u00e2nd Linux Mint \u0219i Elementary OS","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00cen utilitarul <noindex><a rel=\"nofollow\" href=\"https:\/\/www.sudo.ws\/\">sudo<\/a><\/noindex>, utilizat pentru a organiza executarea comenzilor \u00een numele altor utilizatori, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2020\/01\/30\/6\">a fost identificat\u0103<\/a><\/noindex> vulnerabilitate (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-18634\">CVE-2019-18634<\/a><\/noindex>), care permite cre\u0219terea privilegiilor \u00een sistem la utilizatorul root. Problema apare \u00eencep\u00e2nd cu versiunea sudo 1.7.1 doar atunci c\u00e2nd se utilizeaz\u0103 \u00een fi\u0219ierul \/etc\/sudoers op\u021biunea \u00abpwfeedback\u00bb, care este dezactivat\u0103 \u00een mod implicit, dar activat\u0103 \u00een unele distribu\u021bii, cum ar fi Linux Mint \u0219i Elementary OS. Problema a fost rezolvat\u0103 \u00een versiunea <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/sudo-project\/sudo\/releases\/tag\/SUDO_1_8_31\">sudo 1.8.31<\/a><\/noindex>, publicat\u0103 acum c\u00e2teva ore. \u00cen distribu\u021biile vulnerabilitatea r\u0103m\u00e2ne \u00eenc\u0103 nerezolvat\u0103.<\/p>\n<p>Op\u021biunea \u00abpwfeedback\u00bb activeaz\u0103 afi\u0219area caracterului \u00ab*\u00bb dup\u0103 fiecare caracter introdus \u00een timpul introducerii parolei. Din cauza <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/sudo-project\/sudo\/commit\/fa8ffeb17523494f0e8bb49a25e53635f4509078\">unei erori<\/a><\/noindex> implement\u0103rii func\u021biei getln(), definit\u0103 \u00een fi\u0219ierul tgetpass.c, un \u0219ir de parole prea mare, transmis prin fluxul de intrare standard (stdin), poate s\u0103 nu \u00eencap\u0103 \u00een bufferul alocat \u0219i s\u0103 suprascrie alte date din stiv\u0103 \u00een anumite condi\u021bii. Suprasarcina apare \u00een timpul execut\u0103rii codului sudo cu privilegii root.<\/p>\n<p>Suma problemei este c\u0103, \u00een timpul introducerii caracterului special ^U (\u0219tergerea liniei) \u0219i \u00een caz de e\u0219ec al opera\u021biei de scriere, codul responsabil pentru \u0219tergerea caracterelor afi\u0219ate \u00ab*\u00bb reseteaz\u0103 datele despre dimensiunea buffer-ului disponibil, dar nu returneaz\u0103 la valoarea ini\u021bial\u0103 pointerul la pozi\u021bia curent\u0103 din buffer. Un alt factor care contribuie la exploatare este absen\u021ba opririi automate a modului \u00abpwfeedback\u00bb atunci c\u00e2nd datele sunt primite nu de la terminal, ci printr-un flux de intrare (aceast\u0103 neglijen\u021b\u0103 permite crearea condi\u021biilor pentru apari\u021bia unei erori de scriere, de exemplu, pe sistemele cu fluxuri unidirec\u021bionale. <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%9D%D0%B5%D0%B8%D0%BC%D0%B5%D0%BD%D0%BE%D0%B2%D0%B0%D0%BD%D0%BD%D1%8B%D0%B9_%D0%BA%D0%B0%D0%BD%D0%B0%D0%BB\">neatribuite<\/a><\/noindex> eroarea apare atunci c\u00e2nd se \u00eencearc\u0103 s\u0103 se scrie dincolo de sf\u00e2r\u0219itul canalului de citire).<\/p>\n<p>Deoarece atacatorul poate controla complet rescrierea datelor din stiv\u0103, nu este dificil s\u0103 se creeze un exploit care s\u0103 permit\u0103 cre\u0219terea privilegiilor la utilizatorul root. Problema poate fi exploatat\u0103 de orice utilizator, indiferent de permisiunile de utilizare a sudo \u0219i de existen\u021ba unor set\u0103ri specifice utilizatorului \u00een sudoers. Pentru a bloca problema, trebuie s\u0103 ne asigur\u0103m c\u0103 nu exist\u0103 \u00een \/etc\/sudoers setarea \u00abpwfeedback\u00bb \u0219i, dac\u0103 este necesar, s\u0103 o dezactiv\u0103m (\u00abDefaults !pwfeedback\u00bb). Pentru a verifica existen\u021ba problemei, se poate rula codul:<\/p>\n<p>$ perl -e \u2018print((\u00abA\u00bb x 100 . \u00ab\u00bb) x 50)\u2019 | sudo -S id<br \/>\n    Parol\u0103: Fault de segmentare<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52284\">opennet.ro<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 sudo, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-18634), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0434\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u0432\u044b\u043f\u0443\u0441\u043a\u0430 sudo 1.7.1 \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 \u0432 \u0444\u0430\u0439\u043b\u0435 \/etc\/sudoers \u043e\u043f\u0446\u0438\u0438 &#171;pwfeedback&#187;, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0430 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e, \u043d\u043e \u0430\u043a\u0442\u0438\u0432\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0432 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445, \u0442\u0430\u043a\u0438\u0445 \u043a\u0430\u043a Linux Mint \u0438 Elementary OS. [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-55921","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 sudo, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/root-uyazvimost-v-sudo-zatragivayushhaya-linux-mint-i-elementary-os\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Root-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 sudo, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0430\u044f Linux Mint \u0438 Elementary OS | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 sudo, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/root-uyazvimost-v-sudo-zatragivayushhaya-linux-mint-i-elementary-os\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-01-31T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:04:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitate Root \u00een sudo, afect\u00e2nd Linux Mint \u0219i Elementary OS | ProHoster","description":"\u00cen utilitarul sudo, utilizat pentru organizarea execut\u0103rii comenzilor \u00een numele altor utilizatori,","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/root-uyazvimost-v-sudo-zatragivayushhaya-linux-mint-i-elementary-os","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Root-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 sudo, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0430\u044f Linux Mint \u0438 Elementary OS | ProHoster","og:description":"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 sudo, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434 \u043e\u0442 \u0438\u043c\u0435\u043d\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439,","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/root-uyazvimost-v-sudo-zatragivayushhaya-linux-mint-i-elementary-os","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-01-31T21:00:00+00:00","article:modified_time":"2020-02-18T11:04:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"55921","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:34:29","updated":"2022-09-29 19:42:56","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/55921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=55921"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/55921\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=55921"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=55921"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=55921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}