CVE-2019-14287: Critical severity Sudo Project Sudo vulnerability
A flaw was found in sudo before version 1.8.28. When sudo is configured to allow a user to run commands as an arbitrary user via the 'ALL' keyword in a 'Runas' specification, it is possible to run commands as root.
Other sources
A flaw was found in the way sudo implemented running commands with arbitrary user ID. If a sudoers entry is written to allow the attacker to run a command as any user except root, this flaw can be used by the attacker to bypass that restriction.
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw in sudo?
The vulnerability ID for this flaw in sudo is CVE-2019-14287.
What is the severity of CVE-2019-14287?
The severity of CVE-2019-14287 is high.
How does the vulnerability in sudo affect the system?
The vulnerability in sudo allows an attacker with access to a Runas ALL sudoer account to bypass certain policy blacklists and session PAM modules, and can cause incorrect logging.
How can an attacker exploit CVE-2019-14287?
An attacker can exploit CVE-2019-14287 by invoking sudo with a crafted user ID.
Is there a fix available for this vulnerability in sudo?
Yes, the fix for this vulnerability in sudo is version 1.8.28.