Mark CVE-2019-18684 as unimportant (as non-(security)-issue)
An attack is only viable if the attacker can write to fd/3. In the concrete case fd/3 would point to /etc/sudoers. Then the only way to write to /proc/$pid/fd/3 would be to have write permission to /etc/sudoers itself. Thanks: Todd C. Miller for the analysis.
Loading
Please register or sign in to comment