Package "sudo-ldap"
Name: |
sudo-ldap
|
Description: |
Provide limited super user privileges to specific users
|
Latest version: |
1.8.21p2-3ubuntu1.6 |
Release: |
bionic (18.04) |
Level: |
security |
Repository: |
universe |
Head package: |
sudo |
Homepage: |
http://www.sudo.ws/ |
Links
Download "sudo-ldap"
Other versions of "sudo-ldap" in Bionic
Changelog
sudo (1.8.21p2-3ubuntu1.6) bionic-security; urgency=medium
* SECURITY UPDATE: does not escape control characters
- debian/patches/CVE-2023-2848x-1.patch: escape control characters in
log messages and sudoreplay output in docs/sudoers.man.in,
docs/sudoers.mdoc.in, docs/sudoreplay.man.in,
docs/sudoreplay.mdoc.in, include/sudo_compat.h, include/sudo_lbuf.h,
lib/util/lbuf.c, lib/util/util.exp.in, plugins/sudoers/logging.c,
plugins/sudoers/sudoreplay.c.
- debian/patches/CVE-2023-2848x-2.patch: fix regression in
plugins/sudoers/logging.c.
- CVE-2023-28486
- CVE-2023-28487
-- Marc Deslauriers <email address hidden> Tue, 04 Apr 2023 08:44:58 -0400
|
Source diff to previous version |
CVE-2023-28486 |
Sudo before 1.9.13 does not escape control characters in log messages. |
CVE-2023-28487 |
Sudo before 1.9.13 does not escape control characters in sudoreplay output. |
|
sudo (1.8.21p2-3ubuntu1.5) bionic-security; urgency=medium
* SECURITY UPDATE: arbitrary file overwrite via sudoedit
- debian/patches/CVE-2023-22809.patch: do not permit editor arguments
to include -- in plugins/sudoers/editor.c.
- CVE-2023-22809
-- Marc Deslauriers <email address hidden> Mon, 16 Jan 2023 09:40:55 -0500
|
Source diff to previous version |
sudo (1.8.21p2-3ubuntu1.4) bionic-security; urgency=medium
* SECURITY UPDATE: dir existence issue via sudoedit race
- debian/patches/CVE-2021-23239.patch: fix potential directory existing
info leak in sudoedit in src/sudo_edit.c.
- CVE-2021-23239
* SECURITY UPDATE: heap-based buffer overflow
- debian/patches/CVE-2021-3156-pre1.patch: check lock record size in
plugins/sudoers/timestamp.c.
- debian/patches/CVE-2021-3156-pre2.patch: sanity check size when
converting the first record to TS_LOCKEXCL in
plugins/sudoers/timestamp.c.
- debian/patches/CVE-2021-3156-1.patch: reset valid_flags to
MODE_NONINTERACTIVE for sudoedit in src/parse_args.c.
- debian/patches/CVE-2021-3156-2.patch: add sudoedit flag checks in
plugin in plugins/sudoers/policy.c.
- debian/patches/CVE-2021-3156-3.patch: fix potential buffer overflow
when unescaping backslashes in plugins/sudoers/sudoers.c.
- debian/patches/CVE-2021-3156-4.patch: fix the memset offset when
converting a v1 timestamp to TS_LOCKEXCL in
plugins/sudoers/timestamp.c.
- debian/patches/CVE-2021-3156-5.patch: don't assume that argv is
allocated as a single flat buffer in src/parse_args.c.
- CVE-2021-3156
* debian/control: added tzdata to Build-Depends so that the time zone
data directory is present during builds.
-- Marc Deslauriers <email address hidden> Tue, 19 Jan 2021 09:36:00 -0500
|
Source diff to previous version |
CVE-2021-23239 |
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_ed |
CVE-2021-3156 |
Heap-based buffer overflow |
|
sudo (1.8.21p2-3ubuntu1.2) bionic-security; urgency=medium
* SECURITY UPDATE: buffer overflow in sudo when pwfeedback is enabled
- debian/patches/CVE-2019-18634.patch: fix overflow in src/tgetpass.c.
- CVE-2019-18634
-- Marc Deslauriers <email address hidden> Fri, 31 Jan 2020 12:18:41 -0500
|
Source diff to previous version |
CVE-2019-18634 |
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwf |
|
sudo (1.8.21p2-3ubuntu1.1) bionic-security; urgency=medium
* SECURITY UPDATE: privilege escalation via UID -1
- debian/patches/CVE-2019-14287.patch: treat an ID of -1 as invalid
in lib/util/strtoid.c.
- CVE-2019-14287
- debian/patches/CVE-2019-14287-2.patch: fix and add to tests in
lib/util/regress/atofoo/atofoo_test.c,
plugins/sudoers/regress/testsudoers/test5.out.ok,
plugins/sudoers/regress/testsudoers/test5.sh.
- CVE-2019-14287
-- Marc Deslauriers <email address hidden> Thu, 10 Oct 2019 14:32:59 -0400
|
|
About
-
Send Feedback to @ubuntu_updates