|
Bugzilla – Full Text Bug Listing |
| Summary: | Shell Execution | ||
|---|---|---|---|
| Product: | Sudo | Reporter: | Debasisha Padhi <debasisha> |
| Component: | Sudo | Assignee: | Todd C. Miller <Todd.Miller> |
| Status: | RESOLVED INVALID | ||
| Severity: | security | CC: | debasisha |
| Priority: | high | ||
| Version: | 1.6.5 | ||
| Hardware: | IBM | ||
| OS: | AIX | ||
|
Description
Debasisha Padhi
2007-10-30 14:56:55 MDT
You can use the NOEXEC tag for this purpose. See the section on NOEXEC in the sudoers man page. In short, if you do things like: junioradm ALL = NOEXEC:/usr/bin/more The user junioradm will be able to run the more command on any file but more will not be able to execute shell escapes or run the editor. |