Bug 919 - add regex style matching to sudoers
add regex style matching to sudoers
Status: RESOLVED DUPLICATE of bug 578
Product: Sudo
Classification: Unclassified
Component: Sudoers
1.8.27
All Linux
: low enhancement
Assigned To: Todd C. Miller
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-03-19 15:56 MDT by Bdale Garbee
Modified: 2022-02-03 19:34 MST (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bdale Garbee 2020-03-19 15:56:28 MDT
A patch got submitted to the Debian BTS with the following text:

Entries in sudoers files that include * do not behave like shell globs.
When mistakenly used in the argument list it can expand to protected
content, such as /etc/shadow. Most users do not expect this.

This patch adds regex style matching to sudoers to improve security and
tighten the available input.

The complete bug log including links to his code can be found at https://bugs.debian.org/945366
Comment 1 Todd C. Miller 2022-02-03 19:34:00 MST

*** This bug has been marked as a duplicate of bug 578 ***