Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.devel > #100974
| From | Brian Thompson <brian@hashvault.io> |
|---|---|
| Newsgroups | linux.debian.devel |
| Subject | Re: Debian package manager privilege escalation attack |
| Date | 2021-08-12 08:20 +0200 |
| Message-ID | <CLcem-4Xu-5@gated-at.bofh.it> (permalink) |
| References | <CLcem-4Xu-7@gated-at.bofh.it> <CL9Jv-2Nw-1@gated-at.bofh.it> <CLbBD-4vB-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On Thu, 2021-08-12 at 07:38 +0200, Niels Thykier wrote: > Timothy M Butterworth: > > All, > > > > I just ran across this article > > https://blog.ikuamike.io/posts/2021/package_managers_privesc/ I > > tested > > the attacks on Debian 11 and they work successfully giving me a root > > shell prompt. > > > > Tim > > > > Hi Tim, > > All of the attacks presented assumes that the local user has "sudo" > permissions to run apt and use that as the basis for escalating > privileges (not commenting on yum or snap). > > I think it is a good demonstration of how some sudo policies are too > lenient and can be exploited. Though I am not sure this is a bug in > apt, as I do not think apt ever promised to be "safe" to use from a > constrained sudo policy. > Would you agree that there is an issue with sudo access that is enabled by default on most Debian and Debian-based distributions? The bug may not be in apt, but it definitely lives somewhere. > Thanks, > ~Niels > -----BEGIN PGP SIGNATURE----- iQJHBAEBCgAxFiEE9fpVo96/flopdKOfgw2Ncu3Nhn0FAmEUu9UTHGJyaWFuQGhh c2h2YXVsdC5pbwAKCRCDDY1y7c2Gfb8QD/sH4ko8qsI7Dxyf4t8oM7bRWnGeyYXG C+e/7kb8ePKXJcSIspbzlEHefsp/chqjWQnA8f3Kqjdn77eGVecxk5O7cyN0nJyC Ih3LyLvuU2CoeLsPw7+0g4Ta81sdNh22xl/M1V3Fkbg5E1AWL7dSLwuj7LzgH5Fo w/YudfGKiyZD7gtdgOP3rfae0rLsgxklUsZQOSEEHyYGuwWZRhwNimWnytKI9XC2 z4LrAxeW07e3GA/RjUWp86/+Lub7RchirCvkV2HpAFRY88mBQbHGLjskyRma3FQ4 rfkuGOQ8R34MHuth7HeSjzuKQhqQ7FRFbH5n0rPB1O20jnjbtO/0UuQ88Foha2Um +S//kLXXpPEo/52nBGnT9KmRTTaMAmqbZPTuE2F5T2hLtNBhgK8HPEcMpn7jW1vT EYYg3aoNvO6pFe0jL9gGomViS+JoCcFkXQI4xaPqkQchjOkTaQNym8alxDiZqwEk rKq8Fz3mTlMYQHpuTM9qNLPCkTWlMg+mFsEarZJcWtjrHiqIKFFPAH+G9SMqHRxD LUcU0iKcoZtBvtSnDnt8QFhwc9eWPFqitoPihliAkfORC7KMmMJ5QgEd0TN/5r6n LmyVo7n8zF2D1ZwUAty3WfWMpRgx8TC2keXsuLWyqW9EZO/PSQplO86tjzYDYWfg WgY5vDsL7eMzFg== =QmLv -----END PGP SIGNATURE-----
Back to linux.debian.devel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Debian package manager privilege escalation attack Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2021-08-12 05:40 +0200
Re: Debian package manager privilege escalation attack Brian Thompson <brian@hashvault.io> - 2021-08-12 06:00 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 07:50 +0200
Re: Debian package manager privilege escalation attack Brian Thompson <brian@hashvault.io> - 2021-08-12 08:20 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 08:30 +0200
Re: Debian package manager privilege escalation attack Paul Tagliamonte <paultag@debian.org> - 2021-08-12 15:00 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 07:40 +0200
Re: Debian package manager privilege escalation attack Vincent Bernat <bernat@debian.org> - 2021-08-12 08:40 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 08:40 +0200
Re: Debian package manager privilege escalation attack Vincent Bernat <bernat@debian.org> - 2021-08-12 09:00 +0200
Re: Debian package manager privilege escalation attack Ansgar <ansgar@43-1.org> - 2021-08-12 10:40 +0200
Re: Debian package manager privilege escalation attack Vincent Bernat <bernat@debian.org> - 2021-08-12 11:20 +0200
Re: Debian package manager privilege escalation attack Philipp Kern <pkern@debian.org> - 2021-08-12 11:20 +0200
Re: Debian package manager privilege escalation attack David Kalnischkies <david@kalnischkies.de> - 2021-08-12 13:50 +0200
Re: Debian package manager privilege escalation attack Kyle Edwards <kyle.edwards@kitware.com> - 2021-08-12 14:40 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 14:50 +0200
Re: Debian package manager privilege escalation attack Niels Thykier <niels@thykier.net> - 2021-08-12 07:40 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 08:20 +0200
Re: Debian package manager privilege escalation attack Brian Thompson <brian@hashvault.io> - 2021-08-12 08:30 +0200
Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 08:40 +0200
Re: Debian package manager privilege escalation attack Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-08-12 12:30 +0200
Re: Debian package manager privilege escalation attack Philipp Kern <pkern@debian.org> - 2021-08-12 13:50 +0200
Re: Debian package manager privilege escalation attack Marc Haber <mh+debian-devel@zugschlus.de> - 2021-08-12 18:00 +0200
Re: Debian package manager privilege escalation attack Philipp Kern <pkern@debian.org> - 2021-08-12 20:10 +0200
Re: Debian package manager privilege escalation attack Russ Allbery <rra@debian.org> - 2021-08-12 21:10 +0200
Re: Debian package manager privilege escalation attack Brian Thompson <brian@hashvault.io> - 2021-08-12 08:20 +0200
Re: Debian package manager privilege escalation attack Holger Levsen <holger@layer-acht.org> - 2021-08-12 15:20 +0200
Re: Debian package manager privilege escalation attack Holger Levsen <holger@layer-acht.org> - 2021-08-12 18:10 +0200
Re: Debian package manager privilege escalation attack Wouter Verhelst <wouter@debian.org> - 2021-08-16 16:50 +0200
csiph-web