Package "sudo"
Name: |
sudo
|
Description: |
This package is just an umbrella for a group of other packages,
it has no description. Description samples from packages in group:
- Provide limited super user privileges to specific users
|
Latest version: |
1.9.1-1ubuntu1.1 |
Release: |
groovy (20.10) |
Level: |
security |
Repository: |
universe |
Links
Other versions of "sudo" in Groovy
Packages in group
Deleted packages are displayed in grey.
Changelog
sudo (1.9.1-1ubuntu1.1) groovy-security; urgency=medium
* SECURITY UPDATE: dir existence issue via sudoedit race
- debian/patches/CVE-2021-23239.patch: fix potential directory existing
info leak in sudoedit in src/sudo_edit.c.
- CVE-2021-23239
* SECURITY UPDATE: heap-based buffer overflow
- debian/patches/CVE-2021-3156-1.patch: reset valid_flags to
MODE_NONINTERACTIVE for sudoedit in src/parse_args.c.
- debian/patches/CVE-2021-3156-2.patch: add sudoedit flag checks in
plugin in plugins/sudoers/policy.c.
- debian/patches/CVE-2021-3156-3.patch: fix potential buffer overflow
when unescaping backslashes in plugins/sudoers/sudoers.c.
- debian/patches/CVE-2021-3156-4.patch: fix the memset offset when
converting a v1 timestamp to TS_LOCKEXCL in
plugins/sudoers/timestamp.c.
- debian/patches/CVE-2021-3156-5.patch: don't assume that argv is
allocated as a single flat buffer in src/parse_args.c.
- CVE-2021-3156
* debian/control: added tzdata to Build-Depends so that the time zone
data directory is present during builds.
-- Marc Deslauriers <email address hidden> Tue, 19 Jan 2021 09:08:56 -0500
|
CVE-2021-23239 |
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_ed |
CVE-2021-3156 |
Heap-based buffer overflow |
|
About
-
Send Feedback to @ubuntu_updates