TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

sudo buffer overflow in command line unescaping “Baron Samedit”

12 点作者 willlll超过 4 年前

1 comment

Qub3d超过 4 年前
Here&#x27;s a summary of the issue as noted by Twitter user @IanColdwaller:<p>&quot;Heap-based buffer overflow in sudo exploitable by any local user. Can be used to elevate privileges to root, even if user not listed in sudoers file. User auth is not required to exploit the bug&quot;<p>At the very least, one must be logged in to a system to exploit it.<p>Given the modern paradigm of just setting up a hypervisor and giving everyone a virtual playground where they have complete root access, as opposed to a multi-user system, I don&#x27;t expect this to be a terribly big issue.<p>I&#x27;ll still be going through all the CentOS boxes at work tomorrow...