default sudo timeouts too long. Potential risks from gui pov.

Bug #146562 reported by uga
256
Affects Status Importance Assigned to Milestone
kdesudo (Ubuntu)
New
Undecided
Unassigned

Bug Description

Binary package hint: kdesudo

The default sudoers configuration file provided in ubuntu's sudo package doesn't define the password (timeouttimestamp_timeout). This means it allows for a 15 minutes default timeout.

From a terminal's point of view, this doesn't seem to be much of a problem. Those applications run within 15 minutes from the same terminal can run as root without providing a password. It doesn't seem to be much of a problem, as far as the terminal is closed once maintenance is done.

The problem arises when the GUI sudo frontends are being used:

Kubuntu's kdesu has been modded to be using sudo (kdesudo) and system administration applications all use kdesudo for authentication. This means that, once somebody does system maintenance, ANY gui application can run as root without providing any password authentication. Any gui application the user runs, can get access to root privileges, even without asking nor notifying the user about it.

I'd really like to see kdesu/do notifying the user that it's about to run something as root. Or, else, have the default timeout reduced to a safer value, to avoid any potential risks of gui applications taking advantage of gui admin application users.

Revision history for this message
David Portwood (dzportwood) wrote :

This is also the default behavior in ubuntu with gksudo.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.