Can we please stop talking about that sudo bug? It only affects systems using an insane configuration (allow $command as anyone *but* root). I can't come up with any situation where that configuration makes any sense (vs e.g. "allow $command as any member of a given group).
-
Show this thread
-
-
-
Replying to @InfernoDeityInf @marcan42
"allow $command as any member of a given group" http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14287 … i said "given group", not "root group"
1 reply 0 retweets 0 likes -
Replying to @SysAdm_Podcast @InfernoDeityInf
If root is in the given group and you allow sudo to that group then you allow sudo to root, obviously. Not sure what you're trying to get at?
1 reply 0 retweets 0 likes -
Replying to @marcan42 @InfernoDeityInf
because the *exclusion* of root user breaks in this case when it oughtn't. i'm saying in the example you provided, if root user is in the group but you explicitly exclude root as a user (!root), it's still able to be switched to.
1 reply 0 retweets 0 likes
Replying to @SysAdm_Podcast @InfernoDeityInf
No, it won't, because '-1' is not in the group.
7:35 PM - 15 Oct 2019
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.