Ubuntu Security Update USN-7867-1: sudo-rs vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,793
Reaction score
74
Credits
-1,257
It was discovered that sudo-rs incorrectly handled passwords when timeouts occurred and the pwfeedback default was not set. This could result in a partially typed password being output to standard input, contrary to expectations. It was discovered that sudo-rs incorrectly handled the targetpw and rootpw default settings when creating timestamp files. A local attacker could possibly use this issue to bypass authentication in certain configurations.

Continue reading...
 
Top