1. 03 Sep, 2019 1 commit
    • Levente Polyak's avatar
      sudo: restrict PATH to protect against privilege escalation attacks · 1eb1dd41
      Levente Polyak authored and Jelle van der Waa's avatar Jelle van der Waa committed
      
      
      Protect from simple privilege escalation attacks on scripts that are
      granted privileged execution for unprivileged users by restricting
      the PATH to a static set.
      Without doing so, it is a trivial attack to provide a binary used
      by a privileged script that executes former without an absolute path
      to escalate privileges by gaining code execution through that binary.
      
      Anything run with elevated privileges through sudo shall never ever
      have the possibility to pass on the unsanatized PATH from an
      unprivileged user.
      Signed-off-by: Levente Polyak's avatarLevente Polyak <anthraxx@archlinux.org>
      1eb1dd41
  2. 02 Sep, 2019 2 commits
  3. 01 Sep, 2019 5 commits
  4. 31 Aug, 2019 2 commits
  5. 25 Aug, 2019 1 commit
  6. 19 Aug, 2019 1 commit
  7. 17 Aug, 2019 1 commit
  8. 15 Aug, 2019 11 commits
  9. 14 Aug, 2019 4 commits
  10. 13 Aug, 2019 1 commit
  11. 12 Aug, 2019 2 commits
  12. 11 Aug, 2019 9 commits