Back to bug 2175611

Who When What Removed Added
Sandipan Roy 2023-03-06 06:31:57 UTC Blocks 2175273
Sandipan Roy 2023-03-06 06:32:12 UTC CC bgalvani, lrintel, nm-team, rkhan, sukulkar, till
Sandipan Roy 2023-03-06 06:32:31 UTC CC bgalvani, lrintel, nm-team, rkhan, sukulkar, till
Sandipan Roy 2023-03-06 06:49:46 UTC Doc Text A vulnerability was found in systemd package. The systemd package does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
Sandipan Roy 2023-03-06 06:50:25 UTC Depends On 2175624, 2175622, 2175623
RaTasha Tillery-Smith 2023-03-06 14:49:50 UTC Doc Text A vulnerability was found in systemd package. The systemd package does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output. A vulnerability was found in the systemd package. The systemd package does not adequately block local privilege escalation for some Sudo configurations, for example, plausible sudoers files, in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This issue presents a substantial security risk when running systemctl from Sudo because less executes as root when the terminal size is too small to show the complete systemctl output.
Kazu Yoshida 2023-03-15 00:22:37 UTC CC kyoshida
Derrick 2023-06-02 16:00:15 UTC CC derrick.roach.ctr
errata-xmlrpc 2023-06-27 14:58:00 UTC Link ID Red Hat Product Errata RHSA-2023:3837
Francisco De Melo 2023-06-30 19:30:10 UTC CC yaoli
CC fdemeloj
Mike Millson 2023-07-03 18:49:36 UTC CC mmillson
Red Hat Bugzilla 2023-07-07 08:35:47 UTC Assignee security-response-team nobody
Nick Tait 2023-08-11 21:14:19 UTC Fixed In Version systemd 247

Back to bug 2175611