This repository was archived by the owner on May 4, 2024. It is now read-only.
sudoers entries should be prefixed with a digest spec #18
Labels
documentation
Improvements or additions to documentation
Allowing password-less execution of
/usr/local/bin/vde_vmnet
asroot
is a vulnerability when the user has non-sudo write access to/usr/local/bin
(which is typically the case when using homebrew), because they could simply replacevde_vmnet
with any other command or script and then execute that underroot
.This can be mitigated by including a checksum of the executable in the sudo rule, e.g.
should lead to a rule such as (untested):
The text was updated successfully, but these errors were encountered: