Another Sudo Root Privilege Escalation Vulnerability Got Patched, Update Now

Sudo 1.9.5p2 was released today and it addresses two security issues. The first, CVE-2021-3156 (a.k.a. Baron Samedit), was discovered by Qualys Research Labs and could allow local users (sudoers and non-sudoers) to obtain unintended access to the root (system administrator) account.
In addition, the new release patches CVE-2021-23239, a vulnerability discovered in Sudo’s sudoedit utility, which could allow a local attacker to bypass file permissions and determine if a directory exists or not. This security flaw affected Sudo versions before 1.9.5.
-
- Login or register to post comments
Printer-friendly version
- 3880 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
Stunning GNOME 40 Beta is Ready. Download and Test Now!
The GNOME team announced the availability of the official GNOME 40 Beta images in an email announcement. You can download and try the images now to experience the design overhaul.
| Can Linux Run Video Games?
Linux is a widely used and popular open source operating system that was first released back in 1991. It differs from operating systems like Windows and macOS in that it is open source and it is highly customizable through its use of “distributions”. Distributions or “distros” are basically different versions of Linux that can be installed along with the Linux core software so that users can customize their system to fit their specific need. Some of the more popular Linux distributions are Ubuntu, Debian and Fedora.
For many years Linux had the reputation of being a terrible gaming platform and it was believed that users wouldn’t be able to engage in this popular form of entertainment. The main reason for this is that commercially successful games just weren’t being developed for Linux. A few well known video game titles like Doom, Quake and SimCity made it to Linux but for the most part they were overlooked through the 1990’s. However, things have changed a lot since then and there is an every expanding library of popular video games you can play on Linux.
[...]
There are plenty of Windows games you can run on Linux and no reason why you can’t play as well as you do when using Windows. If you are having trouble leveling up or winning the best loot, consider trying AskBoosters for help with your game.
Aside from native Linux games and Windows games there are a huge amount of browser based games that work on any system including Linux.
|
Security: DFI and Canonical, IBM/Red Hat/CentOS and Oracle, Malware in GitHub
| What goes into default Debian?
The venerable locate file-finding utility has long been available for Linux systems, though its origins are in the BSD world. It is a generally useful tool, but does have a cost beyond just the disk space it occupies in the filesystem; there is a periodic daemon program (updatedb) that runs to keep the file-name database up to date. As a recent debian-devel discussion shows, though, people have differing ideas of just how important the tool is—and whether it should be part of the default installation of Debian.
There are several variants of locate floating around at this point. The original is described in a ;login: article from 1983; a descendant of that code lives on in the GNU Find Utilities alongside find and xargs. After that came Secure Locate (slocate), which checks permissions to only show file names that users have access to, and its functional successor, mlocate, which does the same check but also merges new changes into the existing database, rather than recreating it, for efficiency and filesystem-cache preservation. On many Linux distributions these days, mlocate is the locate of choice.
|
BleepingComputer
New Linux SUDO flaw lets local users gain root privileges
Anti-Linux writers rejoice
10-years-old Sudo bug lets Linux users gain root-level access
The original
CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)
Sudo vulnerability allows attackers to gain root privileges...
Sudo vulnerability allows attackers to gain root privileges on Linux systems (CVE-2021-3156)
3 More
10-year-old Sudo Bug Lets Linux Users Gain Root-Level Access
Sudo Flaw Gives Linux Users Root Access | Decipher
Serious 10-year-old flaw in Linux sudo command; a new version patches it | Network World
Critical Vulnerability Patched in 'sudo' Utility...
Critical Vulnerability Patched in 'sudo' Utility...
PSA: If your PC runs Linux, you should update Sudo now
PSA: If your PC runs Linux, you should update Sudo now
An unpleasant sudo vulnerability
An unpleasant sudo vulnerability
Sudo Bug Gives Root Access to Mass Numbers of Linux Systems
Sudo Bug Gives Root Access to Mass Numbers of Linux Systems
Decade-old vulnerability is still affecting most Linux distro
Decade-old vulnerability is still affecting most Linux distros
Cyber Command, NSA warn to patch decade-old sudo vulnerability
Cyber Command, NSA warn to patch decade-old sudo vulnerability
‘One of the most beautiful bugs I’ve seen’: Decade-old sudo bug
‘One of the most beautiful bugs I’ve seen’: Decade-old sudo bug grants Linux root access
Sudo Vulnerability 2021: 'Baron Samedit' Bug on Linux...
Sudo Vulnerability 2021: 'Baron Samedit' Bug on Linux Gives Attackers Free Root-Level Access
Three more pieces
Bug in Linux sudo command could give any user root access
Weekly threat roundup: Apple, SonicWall, Linux Sudo
Decade-Old Sudo Flaw Discovered
Sudo Vulnerability Discovered
Sudo Vulnerability Discovered: How To Protect Your System From Baron Samedit - Front Page Linux
Researchers: Beware of 10-Year-Old Linux Vulnerability
Researchers: Beware of 10-Year-Old Linux Vulnerability
This Week In Security: Sudo, Database Breaches, And Ransomware
This Week In Security: Sudo, Database Breaches, And Ransomware
Linux sudo exploit gives root access
Linux sudo exploit gives root access
"Linux Flaw"
The Linux Flaw you can't afford to Ignore (CVE-2021-3156) [Ed: It is not a "Linux flaw" but a sudo flaw and it affects systems that are not Linux]