Bug 1309976 - closefrom_override sudo option not working
closefrom_override sudo option not working
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: sudo (Show other bugs)
All Linux
medium Severity medium
: rc
: ---
Assigned To: Daniel Kopeček
Dalibor Pospíšil
: Patch
Depends On:
  Show dependency treegraph
Reported: 2016-02-19 01:41 EST by Karel Srot
Modified: 2016-05-10 17:44 EDT (History)
4 users (show)

See Also:
Fixed In Version: sudo-1.8.6p3-23.el6
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 1297062
Last Closed: 2016-05-10 17:44:32 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
proposed patch (1.35 KB, patch)
2016-02-25 08:16 EST, Daniel Kopeček
no flags Details | Diff

  None (edit)
Description Karel Srot 2016-02-19 01:41:55 EST
This is actually present also on RHEL-6, confirmed with sudo-1.8.6p3-20.el6_7.

+++ This bug was initially created as a clone of Bug #1297062 +++

Description of problem:
We have following defined in /etc/sudoers file 

Cmnd_Alias CMDS0 = /bb/sys/package/c/console/current/bb/bin/console
Defaults!CMDS0 closefrom_override

But it seems closefrom_override is not being respected in rhel7.2 (3.10.0-327.3.1.el7.x86_64). The same sudoers file work fine in rhel6.x.

Following error comes when user tries to run the command

sudo: you are not permitted to use the -C option
sudo: you are not permitted to use the -C option

Version of sudo

pny-comdb2lnx4 /root # rpm -qa|grep sudo

Version-Release number of selected component (if applicable):

How reproducible:
Works on RHEL 6, but not on RHEL 7.2

Steps to Reproduce:

Actual results:
sudo: you are not permitted to use the -C option
sudo: you are not permitted to use the -C option
Comment 3 Daniel Kopeček 2016-02-25 08:16 EST
Created attachment 1130534 [details]
proposed patch
Comment 8 errata-xmlrpc 2016-05-10 17:44:32 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.