sudo: Privilege escalation via 'Runas' specification with 'ALL' keyword
Published Oct 17, 2019
8.8
HIGHCVSS 3.1
EPSS 63.76%
Description
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
Affected products
No data.
Configuration 1
- < 1.8.28
Configuration 2
- 29
- 30
- 31
Configuration 3
- 8.0
- 9.0
- 10.0
Configuration 5
- 12.04
- 14.04
- 16.04
- 18.04
- 19.04
Configuration 6
- n/a
Configuration 7
- 4.1
- 4.2
- 8.0
- 6.0
- 7.0
- 7.5
- 7.6
- 7.7
- 8.1
- 8.2
- 8.4
- 5.0
- 6.0
- 7.0
- 6.5
- 6.6
- 7.2
- 7.3
- 7.4
- 7.6
- 7.7
- 8.2
- 8.4
- 7.2
- 7.3
- 7.4
- 7.6
- 7.7
- 8.2
- 8.4
- 6.0
- 7.0
No data.
Red Hat Enterprise Linux 5 Extended Lifecycle Support
sudo-0:1.7.2p1-31.el5_11.1
Fixed · RHSA-2019:4191
Red Hat Enterprise Linux 6
sudo-0:1.8.6p3-29.el6_10.2
Fixed · RHSA-2019:3755
Red Hat Enterprise Linux 6.5 Advanced Update Support
sudo-0:1.8.6p3-12.el6_5.2
Fixed · RHSA-2019:3895
Red Hat Enterprise Linux 6.6 Advanced Update Support
sudo-0:1.8.6p3-15.el6_6.2
Fixed · RHSA-2019:3754
Red Hat Enterprise Linux 7
sudo-0:1.8.23-4.el7_7.1
Fixed · RHSA-2019:3197
Red Hat Enterprise Linux 7.2 Advanced Update Support
sudo-0:1.8.6p7-17.el7_2.2
Fixed · RHSA-2019:3278
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
sudo-0:1.8.6p7-17.el7_2.2
Fixed · RHSA-2019:3278
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
sudo-0:1.8.6p7-17.el7_2.2
Fixed · RHSA-2019:3278
Red Hat Enterprise Linux 7.3 Advanced Update Support
sudo-0:1.8.6p7-23.el7_3.2
Fixed · RHSA-2019:3219
Red Hat Enterprise Linux 7.3 Telco Extended Update Support
sudo-0:1.8.6p7-23.el7_3.2
Fixed · RHSA-2019:3219
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions
sudo-0:1.8.6p7-23.el7_3.2
Fixed · RHSA-2019:3219
Red Hat Enterprise Linux 7.4 Advanced Update Support
sudo-0:1.8.19p2-12.el7_4.1
Fixed · RHSA-2019:3209
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
sudo-0:1.8.19p2-12.el7_4.1
Fixed · RHSA-2019:3209
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
sudo-0:1.8.19p2-12.el7_4.1
Fixed · RHSA-2019:3209
Red Hat Enterprise Linux 7.5 Extended Update Support
sudo-0:1.8.19p2-14.el7_5.1
Fixed · RHSA-2019:3204
Red Hat Enterprise Linux 7.6 Extended Update Support
sudo-0:1.8.23-3.el7_6.1
Fixed · RHSA-2019:3205
Red Hat Enterprise Linux 8
sudo-0:1.8.25p1-8.el8_1
Fixed · RHSA-2019:3694
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
sudo-0:1.8.25p1-4.el8_0.2
Fixed · RHSA-2020:0388
Red Hat OpenShift Container Platform 4
machine-os-content-container
Fixed · RHSA-2019:3941
Red Hat OpenShift Container Platform 4
machine-os-content-container
Fixed · RHSA-2019:3916
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
redhat-release-virtualization-host-0:4.2-15.1.el7
Fixed · RHBA-2019:3248
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
redhat-virtualization-host-0:4.2-20191022.0.el7_6
Fixed · RHBA-2019:3248
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Extended Lifecycle Support | sudo-0:1.7.2p1-31.el5_11.1 | Fixed | RHSA-2019:4191 |
| Red Hat Enterprise Linux 6 | sudo-0:1.8.6p3-29.el6_10.2 | Fixed | RHSA-2019:3755 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | sudo-0:1.8.6p3-12.el6_5.2 | Fixed | RHSA-2019:3895 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | sudo-0:1.8.6p3-15.el6_6.2 | Fixed | RHSA-2019:3754 |
| Red Hat Enterprise Linux 7 | sudo-0:1.8.23-4.el7_7.1 | Fixed | RHSA-2019:3197 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | sudo-0:1.8.6p7-17.el7_2.2 | Fixed | RHSA-2019:3278 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | sudo-0:1.8.6p7-17.el7_2.2 | Fixed | RHSA-2019:3278 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | sudo-0:1.8.6p7-17.el7_2.2 | Fixed | RHSA-2019:3278 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | sudo-0:1.8.6p7-23.el7_3.2 | Fixed | RHSA-2019:3219 |
| Red Hat Enterprise Linux 7.3 Telco Extended Update Support | sudo-0:1.8.6p7-23.el7_3.2 | Fixed | RHSA-2019:3219 |
| Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions | sudo-0:1.8.6p7-23.el7_3.2 | Fixed | RHSA-2019:3219 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | sudo-0:1.8.19p2-12.el7_4.1 | Fixed | RHSA-2019:3209 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | sudo-0:1.8.19p2-12.el7_4.1 | Fixed | RHSA-2019:3209 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | sudo-0:1.8.19p2-12.el7_4.1 | Fixed | RHSA-2019:3209 |
| Red Hat Enterprise Linux 7.5 Extended Update Support | sudo-0:1.8.19p2-14.el7_5.1 | Fixed | RHSA-2019:3204 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | sudo-0:1.8.23-3.el7_6.1 | Fixed | RHSA-2019:3205 |
| Red Hat Enterprise Linux 8 | sudo-0:1.8.25p1-8.el8_1 | Fixed | RHSA-2019:3694 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | sudo-0:1.8.25p1-4.el8_0.2 | Fixed | RHSA-2020:0388 |
| Red Hat OpenShift Container Platform 4 | machine-os-content-container | Fixed | RHSA-2019:3941 |
| Red Hat OpenShift Container Platform 4 | machine-os-content-container | Fixed | RHSA-2019:3916 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | redhat-release-virtualization-host-0:4.2-15.1.el7 | Fixed | RHBA-2019:3248 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | redhat-virtualization-host-0:4.2-20191022.0.el7_6 | Fixed | RHBA-2019:3248 |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw only affects specific, non-default configurations of sudo, in which sudoers configuration entry allows a user to run a command as any user except root, for example: someuser myhost = (ALL, !root) /usr/bin/somecommand This configuration allows user "someuser" to run somecommand as any other user except root. However, this flaw also allows someuser to run somecommand as root by specifying the target user using the numeric id of -1. Only the specified command can be run, this flaw does NOT allow user to run other commands that those specified in the sudoers configuration. Any other configurations of sudo (including configurations that allow user to run commands as any user including root and configurations that allow user to run command as a specific other user) are NOT affected by this flaw. Red Hat Virtualization Hypervisor includes an affected version of sudo, however the default configuration is not vulnerable to this flaw.
Red Hat mitigation
This vulnerability only affects configurations of sudo that have a runas user list that includes an exclusion of root. The most simple example is: ~~~ someuser ALL=(ALL, !root) /usr/bin/somecommand ~~~ The exclusion is specified using an excalamation mark (!). In this example, the "root" user is specified by name. The root user may also be identified in other ways, such as by user id: ~~~ someuser ALL=(ALL, !#0) /usr/bin/somecommand ~~~ or by reference to a runas alias: ~~~ Runas_Alias MYGROUP = root, adminuser someuser ALL=(ALL, !MYGROUP) /usr/bin/somecommand ~~~ To ensure your sudoers configuration is not affected by this vulnerability, we recommend examining each sudoers entry that includes the `!` character in the runas specification, to ensure that the root user is not among the exclusions. These can be found in the /etc/sudoers file or files under /etc/sudoers.d.
References (41)
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00042.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00047.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/154853/Slackware-Security-Advisory-sudo-Updates.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2019/10/14/1 mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/24/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/29/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/09/14/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHBA-2019:3248 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3197 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3204 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3205 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3209 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3219 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3278 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3694 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3754 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3755 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3895 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3916 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3941 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4191 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0388 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-14287 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1760531 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2019/10/msg00022.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IP7SIOAVLSKJGMTIULX52VQUPTVSC43U/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPLAM57TPJQGKQMNG6RHFBLACD6K356N/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TUVAOZBYUHZS56A5FQSCDVGXT7PW7FL2/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-14287
- https://resources.whitesourcesoftware.com/blog-whitesource/new-vulnerability-in-sudo-cve-2019-14287 x_refsource_MISCThird Party Advisory
- https://seclists.org/bugtraq/2019/Oct/20 mailing-listx_refsource_BUGTRAQIssue TrackingMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Oct/21 mailing-listx_refsource_BUGTRAQIssue TrackingMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202003-12 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20191017-0003/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K53746212?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03976en_us x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4154-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14287
- https://www.debian.org/security/2019/dsa-4543 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.openwall.com/lists/oss-security/2019/10/15/2 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- https://www.sudo.ws/alerts/minus_1_uid.html x_refsource_CONFIRMExploitVendor Advisory
Change history (0)
No recorded changes yet.