¡¾Ô­´´Îó²î¡¿sudo rootȨÏÞÈÆ¹ý(CVE-2019-14287)

Ðû²¼Ê±¼ä 2019-10-15

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


1¡¢Åä¾°ÐÎò


Çå¾²Ñо¿Ö°Ô±ÔÚsudoÖз¢Ã÷ÁËÒ»¸öÎó²î£¬£¬£¬ £¬£¬ £¬£¬£¬ËüÊÇ×îÖ÷Òª£¬£¬£¬ £¬£¬ £¬£¬£¬¹¦Ð§×îǿʢÇÒ×î³£Óõij£ÓóÌÐòÖ®Ò»£¬£¬£¬ £¬£¬ £¬£¬£¬Ëü×÷ΪװÖÃÔÚÏÕЩËùÓлùÓÚUNIXºÍLinuxµÄ²Ù×÷ϵͳÉϵĽ¹µãÏÂÁî¶ø·ºÆð¡£¡£¡£


2¡¢Îó²îÁбí


CVE ID  £º   CVE-2019-14287
Îó²îÆ·¼¶£º   ÖÐΣ
Ó°Ïì¹æÄ££º   sudo 1.8.28֮ǰµÄ°æ±¾

3¡¢Îó²îÏêÇé


¸ÃÎó²îÊÇsudoÇå¾²Õ½ÂÔÈÆ¹ýÎÊÌ⣬£¬£¬ £¬£¬ £¬£¬£¬×ÝÈ»¡° sudoersÉèÖá±Ã÷ȷեȡÁËrootÓû§»á¼û£¬£¬£¬ £¬£¬ £¬£¬£¬¸ÃÎó²îÒ²¿ÉÄÜÔÊÐí¶ñÒâÓû§»ò³ÌÐòÒÔrootÓû§Éí·ÝÔÚÄ¿µÄLinuxϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£


sudo´ú±í¡°³¬µÈÓû§¡±£¬£¬£¬ £¬£¬ £¬£¬£¬ËüÊÇÒ»¸öϵͳÏÂÁ£¬£¬ £¬£¬ £¬£¬£¬ÔÊÐíÓû§ÒÔÆäËûÓû§µÄÌØÈ¨ÔËÐÐÓ¦ÓóÌÐò»òÏÂÁ£¬£¬ £¬£¬ £¬£¬£¬¶øÎÞÐèÇл»ÇéÐΡ£¡£¡£Í¨³£ÒÔrootÓû§Éí·ÝÔËÐÐÏÂÁî¡£¡£¡£


ĬÈÏÇéÐÎÏ£¬£¬£¬ £¬£¬ £¬£¬£¬ÔÚ´ó´ó¶¼Linux¿¯ÐаæÖУ¬£¬£¬ £¬£¬ £¬£¬£¬ÈçÏÂͼËùʾ£¬£¬£¬ £¬£¬ £¬£¬£¬/etc/sudoersÎļþÖÐRunAs¹æ·¶ÖеÄALLÒªº¦×ÖÔÊÐíadmin»òsudo×éÖеÄËùÓÐÓû§ÒÔϵͳÉϵÄÈκÎÓÐÓÃÓû§Éí·ÝÔËÐÐÈκÎÏÂÁî¡£¡£¡£

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ÈôÊÇÆ¾Ö¤±ê×¼ÉèÖÃϵͳսÂÔ£¬£¬£¬ £¬£¬ £¬£¬£¬Ôò²»Ò×Êܵ½¹¥»÷¡£¡£¡£ÈôÊÇÊǷDZê×¼ÉèÖ㬣¬£¬ £¬£¬ £¬£¬£¬ÀýÈ磺Runas¹æ·¶Ã÷ȷեȡroot»á¼û£¬£¬£¬ £¬£¬ £¬£¬£¬Runas¹æ·¶ÖÐÊ×ÏÈÁгöALLÒªº¦×Ö£¬£¬£¬ £¬£¬ £¬£¬£¬ÄÇôsudoȨÏÞµÄÓû§¾Í¿ÉÒÔʹÓÃËüÀ´ÒÔrootÉí·ÝÔËÐÐÏÂÁî¡£¡£¡£ÈôÊÇͨ¹ý-uÑ¡ÏîÖ¸¶¨µÄÓû§IDÔÚÃÜÂëÊý¾Ý¿âÖв»±£´æ£¬£¬£¬ £¬£¬ £¬£¬£¬Òò´Ë²»»áÔËÐÐÈκÎPAM»á»°Ä£¿£¿£¿é¡£¡£¡£

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

4¡¢ÐÞ¸´½¨Òé


Ç¿ÁÒ½¨ÒéÉý¼¶µ½×îа汾£¬£¬£¬ £¬£¬ £¬£¬£¬ÏêϸµÄ¿¯Ðа潨Òé²Î¿¼¹ÙÍø¸ø³öµÄ½¨Òé¡£¡£¡£


Red Hat Enterprise Linux / CentOS
https://access.redhat.com/security/cve/CVE-2019-14287

Ubuntu
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-14287.html

SUSE / openSUSE
https://www.suse.com/security/cve/CVE-2019-14287.html

5¡¢²Î¿¼Á´½Ó


https://thehackernews.com/2019/10/linux-sudo-run-as-root-flaw.html
https://www.sudo.ws/alerts/minus_1_uid.html