Blocking Sudo Exploits with Fapolicyd

(jwgarber.ca)

2 points | by jwgarber 16 hours ago

2 comments

  • Modified3019 15 hours ago
    Does ‘doas’ avoid these kinds of exploits, or is it just as vulnerable?
    • jwgarber 15 hours ago
      It's also an SUID binary so in theory the same thing could happen. However it's much simpler than sudo so the odds of a bug creeping in like this are much smaller.