Linux Sudo Command Bug Enabled Hackers To Gain Root Access

One of the most important commands in Linux contained a rather nasty security flaw that could have let malicious types gain root access to the operating system. The bug, which has since been squashed by developers, was found in the sudo command that is used by developers to carry out tasks and run stuff with elevated privileges. Sudo only enables this if users of the command have the right permissions to do so on a Linux machine or know the root user’s password. But the command appears to have been a little too effective. It could have allowed hackers with enough access to run sudo on a Linux machine to gain root access even if the configuration of Linux they were accessing would not have normally allowed it.

 

Subscribe
Notify of
guest

1 Expert Comment
Most Voted
Newest Oldest
Inline Feedbacks
View all comments
Jake Moore
Jake Moore , Cybersecurity Specialist
InfoSec Expert
October 16, 2019 1:27 pm

Attacks such as this require physical access and the correct privileges on the machine. So these attacks are also preventable in their majority.

However, the insider threat is becoming more and more apparent in the workplace and this will threaten businesses who bypass the patch.

Insiders with knowledge can be extremely damaging and can create far more problems than external attacks. This highlights the importance of limiting user privileges where possible. An attack can easily happen, conducted by a disgruntled employee or just a bad apple, so this risk must be mitigated where possible. It goes without saying a patch is an absolute must on these versions too.

Last edited 2 years ago by Jake Moore
Information Security Buzz
1
0
Would love your thoughts, please comment.x
()
x