Permissions, Privileges, and Access Controls in Sudo - CVE-2019-19234
Published: December 20, 2019 / Updated: January 30, 2020
Vulnerability details
The vulnerability allows a local user to impersonate other users on the system.
The vulnerability exists due to incorrect handling of the blocked users (e.g., by using the ! character in the shadow file instead of a password hash) in sudo. A local user with access to a Runas ALL sudoer account can impersonate blocked users.
Affected software
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
IBM Integrated Analytics System
Oracle Solaris
Fedora
sudo
How to mitigate CVE-2019-19234
IBM Integrated Analytics System - update to 1.0.31.0
sudo - addressed in versions 1.9.0-0.1.b1.fc31, 1.9.0-0.1.b1.fc32