3 ms·
Trading one class of vulnerabilities for another. Memory corruption bugs for logic bugs. The disclaimer on the README is correct, this is not secure. From a fiv
by netsec_burn 3y ago
Trading one class of vulnerabilities for another. Memory corruption bugs for logic bugs. The disclaimer on the README is correct, this is not secure. From a five minute cursory review I identified that you can enumerate file paths in directories that you don't have privileges to view (prior to sudo-rs authenticating you via PAM).
- rnijveld 3y agoWe’d love to get a report for this! While we are sure we will make bugs (which is also why we have the notice up on the repository, and you have to go through some hoops in order to use it), we also think that we can try and come up with an implementation that is safer in other ways as well. And if nothing else then at least some good attention will hopefully be drawn to sudo, because it can use a little care and attention.