Blog | G5 Cyber Security

A recently discovered Linux flaw could be exploited by Sudo Users to gain Root Privileges

Security researchers at Qualys Security have discovered a Linux flaw that could be exploited to gain root privileges and overwrite any file on the filesystem. The high severity flaw, tracked as CVE-2017-1000367, resides in the Sudos get_process_ttyname() for Linux and is related to the way Sudo parses tty information from the process status file in the proc file. The flaw affects all Sudo versions from 1.6p7 through 1.8.8p and the issue was rated with a CVSS33 Score of 78.”]

Source: http://securityaffairs.co/wordpress/59606/hacking/linux-flaw.html

Exit mobile version