It only affects configurations that restrict access as root *but allow access as -1*, i.e. use ALL. The way you phrase it it sounds like it affects any config that allows access as a user or group that isn't root.
What everyone took from that line is "a sudoers config which lets you run something as www-data lets you run it as root" which is not the case.
-
-
A much more understandable way of saying it, which the original report should've used, is "a configuration which allows users to run a command as a set of user IDs including -1, but not root" (which happens to in practice only be ALL default-any configs).
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
This Tweet is unavailable.
-
Who the heck lets www-data impersonate all users? That makes no sense. The point is it basically applies to no real configs.
- Show replies
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.