Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

3
  • A small follow-up question: visudo(8) says this about the env_editor setting: "visudo is typically run as root so this option may allow a user with visudo privileges to run arbitrary commands as root without logging", i.e. concern has been shown that (with this setting enabled) you could make malicious use of the editor running as root. Commented May 21 at 8:30
  • Your point is that if you can run visudo, there is no point restraining you from accessing broader root privileges, which is why visudo doesn't block shell escapes etc. But here, the man page seems to want to restrain the choice of what text editor you use with visudo, because you could access broader root privileges without being logged. Isn't there a contradiction in intent, here, then? Commented May 21 at 8:30
  • 6
    I think the key point is "without logging" - so the concern is that you might accidentally run commands as root without logging them via sudo. A cautious admin might want to restrict such accidents. But they can't stop deliberate actions. Commented May 21 at 8:56