[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: visudo?



On Tue, Dec 09, 2003 at 09:57:11PM +0100, Jan Lühr wrote:
> ja hallo erstmal,..
> 
> auf mehreren Internetseiten (haupsächlich für Anfänger und ausschließlich bei 
> anderen Disitributionen= wird davor gewarnt die Datei /etc/sudoers mit einem 
> beliebigen Editor zu editieren. Ich habe mir schon vor einiger Zeit meine 
> sudoers ohne Probleme mit joe angelegt.
> Was steht hinter visudo? Warum gibt es diesen Editor bei Woody nicht?

Hmm Google sagt:

visudo edits the sudoers file in a safe fashion, analogous to
vipw(8). visudo locks the sudoers file against multiple simultaneous
edits, provides basic sanity checks, and checks for parse errors. If
the sudoers file is currently being edited you will receive a
message to try again later.

There is a hard-coded list of editors that visudo will use set at
compile-time that may be overridden via the editor sudoers Default
variable. This list defaults to the path to vi(1) on your system, as
determined by the configure script. Normally, visudo does not honor
the EDITOR or VISUAL environment variables unless they contain an
editor in the aforementioned editors list. However, if visudo is
configured with the --with-enveditor flag or the enveditor Default
variable is set in sudoers, visudo will use any the editor defines
by EDITOR or VISUAL. Note that this can be a security hole since it
allows the user to execute any program they wish simply by setting
EDITOR or VISUAL.

> mfG Jan Lühr

Baba
Thorsten

-- 
Thorsten Gowik
mailto:thg-flat@t-online.de
                                                                                
The cause of the problem is:
We ran out of dial tone and we're and waiting
for the phone company to deliver another bottle.



Reply to: