From 51ed7dba4573f573a73cf100021f185c1d140715 Mon Sep 17 00:00:00 2001 From: nodiscc Date: Sat, 7 Mar 2020 13:51:13 +0100 Subject: [PATCH] sudo: do not trust user-defined $PATH, use standard system binaries PATH --- config/includes.chroot/etc/sudoers.d/secure_path | 1 + 1 file changed, 1 insertion(+) create mode 100644 config/includes.chroot/etc/sudoers.d/secure_path diff --git a/config/includes.chroot/etc/sudoers.d/secure_path b/config/includes.chroot/etc/sudoers.d/secure_path new file mode 100644 index 0000000..0790a25 --- /dev/null +++ b/config/includes.chroot/etc/sudoers.d/secure_path @@ -0,0 +1 @@ +Defaults secure_path="/usr/sbin:/usr/bin:/sbin:/bin"