Skip to content

Commit

Permalink
Add sudoedit flag checks in plugin that are consistent with front-end.
Browse files Browse the repository at this point in the history
Don't assume the sudo front-end is sending reasonable mode flags.
These checks need to be kept consistent between the sudo front-end
and the sudoers plugin.
  • Loading branch information
millert committed Jan 23, 2021
1 parent b301b46 commit c4d3840
Showing 1 changed file with 8 additions and 1 deletion.
9 changes: 8 additions & 1 deletion plugins/sudoers/policy.c
Expand Up @@ -88,10 +88,11 @@ parse_bool(const char *line, int varlen, int *flags, int fval)
int
sudoers_policy_deserialize_info(void *v)
{
const int edit_mask = MODE_EDIT|MODE_IGNORE_TICKET|MODE_NONINTERACTIVE;
struct sudoers_open_info *info = v;
char * const *cur;
const char *p, *errstr, *groups = NULL;
const char *remhost = NULL;
char * const *cur;
int flags = 0;
debug_decl(sudoers_policy_deserialize_info, SUDOERS_DEBUG_PLUGIN);

Expand Down Expand Up @@ -348,6 +349,12 @@ sudoers_policy_deserialize_info(void *v)
#endif
}

/* Sudo front-end should restrict mode flags for sudoedit. */
if (ISSET(flags, MODE_EDIT) && (flags & edit_mask) != flags) {
sudo_warnx(U_("invalid mode flags from sudo front end: 0x%x"), flags);
goto bad;
}

user_gid = (gid_t)-1;
user_sid = (pid_t)-1;
user_uid = (gid_t)-1;
Expand Down

1 comment on commit c4d3840

@felixhalim
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alright, now onto this commit #cs4239rocks!

Please sign in to comment.