|
Bugzilla – Full Text Bug Listing |
| Summary: | sudoers wildcard character(*) is unusably dangerous in command line arguments | ||
|---|---|---|---|
| Product: | Sudo | Reporter: | Dave Hicks <david.hicks> |
| Component: | Sudoers | Assignee: | Todd C. Miller <Todd.Miller> |
| Status: | RESOLVED FIXED | ||
| Severity: | normal | CC: | bdale, cyrille.lefevre-lists, david.hicks, ed-sudo |
| Priority: | normal | ||
| Version: | 1.8.6 | ||
| Hardware: | All | ||
| OS: | All | ||
|
Description
Dave Hicks
2012-11-05 12:12:32 MST
I have just received the following response to the Quest case I raised for the same issue (1088167) : '...I have passed your information Todd with the below reply "The only real fix for this is to add regular expression support to the sudoers file. The proposed replacement sudoers file format (which is RBAC-based) already specifies this and does not have wildcard support at all. I'm planning to add POSIX regular expression support for sudo 1.8.7." ' This is great news, thanks in advance Todd, but I have a couple more questions : 1. What do you mean by an RBAC-based sudoers file format? 2. Are Red Hat already aware of your intention to add this to 1.8.7? I believe there was a recent comment from their guy along the lines that he would implement it if you weren't planning to soon (just making sure you're not both doing it at the same time) Thanks again Sudo 2.0 will include an RBAC-based policy format. The design document is located at http://www.sudo.ws/sudo/sudo-rbac.html. I was not aware that Red Hat was planning to add regexp support so they are probably not aware of my plans either. Hello, Can this patch be included in the meantime please? https://www.sudo.ws/pipermail/sudo-workers/2019-March/001232.html I believe it would solve wildcard issues and reduces complexity. Ed Hi, a similar patch has been rejected years ago : https://www.sudo.ws/pipermail/sudo-workers/2016-March/date.html Regards I don't know if that's a rejection: "I'm going to have to think about this a bit." If the fuller solution isn't considered, maybe a smaller minimal solution could be. I'm hoping something can be done, and I'm willing to put energy into it to help. Linking to the github issue (which links here): https://github.com/sudo-project/sudo/issues/15 *** Bug 919 has been marked as a duplicate of this bug. *** Sudo 1.9.10 will include regular expression support. Sudo 1.9.10 includes regular expression support. |