USN-8803-1: Sudo vulnerability
Ubuntu warned Sudo can skip intercept checks, letting local users bypass policy and logging.
Ubuntu Security Notice USN-8803-1 describes a Sudo vulnerability found by Guannan Wang, Zhanpeng Liu, and Guancheng Li. Sudo failed to apply intercept policy checks when commands were executed under certain circumstances. A local attacker already permitted to run specific commands could bypass policy enforcement and logging and execute unauthorized programs. The notice does not name a CVE or report exploitation in the wild.
- Sudo failed to apply intercept policy checks in some executions.
- A permitted local user could bypass policy enforcement and logging.
- Ubuntu published the issue as USN-8803-1; the notice names no CVE.
Guannan Wang, Zhanpeng Liu, and Guancheng Li discovered that Sudo failed to apply intercept policy checks when commands were executed under certain circumstances. A local attacker permitted to run specific commands could possibly use this issue to bypass policy enforcement and logging, executing unauthorized programs.
This source does not provide full text. Read it at ubuntu.com.