this post was submitted on 04 Jul 2025
31 points (100.0% liked)

Cybersecurity

7789 readers
30 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] henfredemars@infosec.pub 12 points 1 week ago* (last edited 1 week ago)

“The issue can only be leveraged with specific configurations using the Host or Host_Alias directives, which are commonly used in enterprise environments,” Stratascale warned.

“The issue arises from allowing an unprivileged user to invoke chroot() on a writable, untrusted path under their control. Sudo calls chroot() several times, regardless of whether the user has corresponding Sudo rule configured,” Stratascale explained.

Although it’s classed only as a low-severity bug, users are urged to update to Sudo 1.9.17p1 or later to mitigate the issue.