Can we please stop talking about that sudo bug? It only affects systems using an insane configuration (allow $command as anyone *but* root). I can't come up with any situation where that configuration makes any sense (vs e.g. "allow $command as any member of a given group).
-
Show this thread
-
I wouldn't be surprised if the number of systems affected by the vuln that *aren't* already intrinsically vulnerable to nasty privescs because the configuration is a terrible idea when working as intended is, well, essentially 0.
3 replies 5 retweets 57 likesShow this thread -
Replying to @marcan42
In a well-closed system, sudo is used precisely to give very selective access to a certain account and / or a certain command. It is precisely those systems that will suffer from this bug. So it hits where it hurts the most.
1 reply 0 retweets 0 likes
No, because the bug only affects sudoers files configured to allow people to run a command as *literally anyone but root*. Not "one user". Literally "any user, including numeric users, except root". That kind of configuration makes *no sense*.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.