PSA: buffer overflow in sudo; allows for local privesc even when a user is not in sudoers
https://www.sudo.ws/alerts/unescape_overflow.html
as a temporary workaround to restrict it to only the users who should be allowed to use it, one can use POSIX ACLs:
chmod 4750 /usr/bin/sudo
setfacl -m g:allow-groupid:rx /usr/bin/sudo or setfacl -m u:allow-userid:rx /usr/bin/sudo
I'm Elfi! I'm a fair folk, magical moth, greyace girl, greenhorn gamedev, in my thirties and , and ADHD+ASD+EDS. Disclosure: white
💕 Aine @SophicLeech
💕 Agi @AgiDine
💕 Jenny @Esme
💕 Cherry @deejvalen
Icon by @Zwiebelprinz, header from Liar Princess and the Blind Prince by NIS