• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

Patches available for Linux Sudo vulnerability

3177

Red Hat, Debian and other Linux distributions released patches yesterday for high-severity vulnerability in sudo that could be abused by a local attacker to gain root privileges. Sudo is a program for Linux and UNIX systems that allows standard users to run specific commands as a superuser, such as adding users or performing system updates.

Researchers at Qualys found the vulnerability in sudo’ s get_process_ttyname function that allows a local attacker with sudo privileges to run commands as root or elevate privileges to root.

“ On Linux systems, sudo parses the /proc/[pid]/stat file to determine the device number of the process’ s tty (field 7). The fields in the file are space-delimited, but it is possible for the command name (field 2) to include white space (including newline), which sudo does not account for,” the sudo advisory said. “ A user with sudo privileges can cause sudo to use a device number of the user’ s choosing by creating a symbolic link from the sudo binary to a name that contains a space, followed by a number.”

Red Hat security team has released an issue stating that if the issue is left unresolved would attacker to circumvent the controls and do more than that. The attacker has to already be on a server and grant access to commands via sudo for the vulnerability to be exploited.

Red Hat said it released fixes yesterday for Red Hat Enterprise Linux 6, as well as Red Hat Enterprise Linux 7. Other distributions such as Debian, SUSE Linux were also patched successfully.

Tags:
julian
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 5 )

Q

What is a list of affected for Linux distro from Linux sudo vulnerability?

A

The following list of affected for Linux distro from Linux sudo vulnerability Hat Enterprise Linux 5 (including clones such as CentOS/Oracle/Scientific Linux 5)
Red Hat Enterprise Linux 6 (including clones such as CentOS/Oracle/Scientific Linux 6)
Red Hat Enterprise Linux 7 (including clones such as CentOS/Oracle/Scientific Linux 7)
Debian Linux wheezy
Debian Linux Jessie
Debian Linux stretch
Debian Linux buster, sid

Q

How to Fix the Meltdown on an Amazon Linux running on AWS

A

Just run yum command:
# yum update kernel
# reboot

Q

How to Fix the Meltdown on Suse Enterprise Linux Server 12-SP3?

A

Execute the zypper command to Fix the Meltdown on Suse Enterprise Linux Server 12-SP3,
# zypper in -t patch SUSE-SLE-SERVER-12-SP3-2018-12=1
### [ To bring your system up-to-date ] ###
# zypper patch
# reboot

Q

How to apply microcode update supplied by Intel on Linux

A

For apply the microcode update supplied by Intel on Linux, use the following link as given below "https://www.cyberciti.biz/faq/install-update-intel-microcode-firmware-linux/"

Q

How to install Intel microcode firmware on Linux using a package manager

A

Tool to transform and deploy CPU microcode update for x86/amd64 comes with Linux. The procedure to install AMD or Intel microcode firmware on Linux is as follows:

Open the terminal app
Debian/Ubuntu Linux user type: sudo apt install intel-microcode
CentOS/RHEL Linux user type: sudo yum install microcode_ctl

Related Tutorials in Patches available for Linux Sudo vulnerability

Related Tutorials in Patches available for Linux Sudo vulnerability

sudo command in Linux with examples
sudo command in Linux with examples
Jun 18, 2016
How to configure two-factor authentication using sudo in Linux
How to configure two-factor authentication using sudo in Linux
Aug 2, 2016

Related Forums in Patches available for Linux Sudo vulnerability

Related Forums in Patches available for Linux Sudo vulnerability

Dpkg
michael class=
E: dpkg was interrupted, you must manually run 'sudo dpkg --configure -a' to correct the problem
Dec 14, 2018
Linux
nathan class=
How to restrict the user to install packages in linux
Mar 2, 2017
Web Server
christian class=
Tool to scan the vulnerabilities in web server
Apr 21, 2017
Sudo
lucas class=
How to enable wheel group and add users
Feb 6, 2017
Ubuntu
caden class=
How to set a root password in Ubuntu 18.10
Apr 9, 2019
Sudo
connor class=
how to run root commands without password from sudo user
Feb 22, 2017
CentOS
connor class=
How to add a normal user into the sudoers file On CentOS 7.6
May 31, 2019
Breach-vulnerability
markdjokovic class=
clear the frozen emails in exim
Sep 26, 2018

Related News in Patches available for Linux Sudo vulnerability

Related News in Patches available for Linux Sudo vulnerability

Cisco releases patches for several of its products
Cisco releases patches for several of its products
Apr 7, 2017
Schools are the most common cybercrime targets - ESET
Schools are the most common cybercrime targets - ESET
May 3, 2017
Samba vulnerability calls to mind WannaCry fears to Linux/ UNIX
Samba vulnerability calls to mind WannaCry fears to Linux/ UNIX
May 30, 2017
Patches available for Linux Sudo vulnerability
Patches available for Linux Sudo vulnerability
Jun 1, 2017
Yahoo banishes ImageMagick software after it was found vulnerable to data exfiltration
Yahoo banishes ImageMagick software after it was found vulnerable to data exfiltration
May 24, 2017
New Security Breach at Avast Aimed at Its Ccleaner Software
New Security Breach at Avast Aimed at Its Ccleaner Software
Oct 26, 2019
8.7 million customer Data Breached from Russian ISP
8.7 million customer Data Breached from Russian ISP
Oct 15, 2019
Data Breach in Sabre: Hotel reservation information intruded
Data Breach in Sabre: Hotel reservation information intruded
May 4, 2017
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help David Lopez Guillen ?
Ayuda urgente instale SSL para servidor Opensuse y ahora no funciona tengo servicio web

hola segui este tutorial para tener un certificado ssl y ahora no se ve mi app en la red, espero alguien pueda ayudarme, tengo M9oodle en3.5 en un servidor open suse y ahora no funciona por favor ayuda.

https://www.linuxhelp.com/how-to-create-ssl-certificate-in-opensuse

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.