obra’s avatarobra’s Twitter Archive—№ 41,671

  1. This is why we can’t have nice things. sudo.ws/alerts/unescape_overflow.html
    1. …in reply to @obra
      “A serious heap-based buffer overflow has been discovered in sudo that is exploitable by any local user. […] The bug can be leveraged to elevate privileges to root, even if the user is not listed in the sudoers file. User authentication is not required to exploit the bug.”