UbuntuUpdates.org

Package "sudo"

Name: sudo

Description:

Provide limited super user privileges to specific users

Latest version: 1.9.9-1ubuntu2.4
Release: jammy (22.04)
Level: security
Repository: main
Homepage: https://www.sudo.ws/

Links


Download "sudo"


Other versions of "sudo" in Jammy

Repository Area Version
base main 1.9.9-1ubuntu2
base universe 1.9.9-1ubuntu2
security universe 1.9.9-1ubuntu2.4
updates main 1.9.9-1ubuntu2.4
updates universe 1.9.9-1ubuntu2.4

Changelog

Version: 1.9.9-1ubuntu2.4 2023-04-11 15:06:54 UTC

  sudo (1.9.9-1ubuntu2.4) jammy-security; urgency=medium

  * SECURITY UPDATE: does not escape control characters
    - debian/patches/CVE-2023-2848x-1.patch: escape control characters in
      log messages and sudoreplay output in docs/sudoers.man.in,
      docs/sudoers.mdoc.in, docs/sudoreplay.man.in,
      docs/sudoreplay.mdoc.in, include/sudo_lbuf.h,
      lib/eventlog/eventlog.c, lib/iolog/iolog_json.c, lib/util/lbuf.c,
      lib/util/util.exp.in, plugins/sudoers/sudoreplay.c.
    - debian/patches/CVE-2023-2848x-2.patch: fix regression in
      lib/eventlog/eventlog.c.
    - CVE-2023-28486
    - CVE-2023-28487

 -- Marc Deslauriers <email address hidden> Mon, 03 Apr 2023 14:00:44 -0400

Source diff to previous version
CVE-2023-28486 Sudo before 1.9.13 does not escape control characters in log messages.
CVE-2023-28487 Sudo before 1.9.13 does not escape control characters in sudoreplay output.

Version: 1.9.9-1ubuntu2.3 2023-03-02 16:07:05 UTC

  sudo (1.9.9-1ubuntu2.3) jammy-security; urgency=medium

  * SECURITY UPDATE: double free with per-command chroot sudoers rules
    - debian/patches/CVE-2023-27320.patch: don't free user_cmnd twice in
      MANIFEST, plugins/sudoers/match_command.c,
      plugins/sudoers/regress/fuzz/fuzz_sudoers.c,
      plugins/sudoers/regress/testsudoers/test20.out.ok,
      plugins/sudoers/regress/testsudoers/test20.sh,
      plugins/sudoers/testsudoers.c,
      plugins/sudoers/visudo.c.
    - CVE-2023-27320

 -- Marc Deslauriers <email address hidden> Wed, 01 Mar 2023 08:59:37 -0500

Source diff to previous version
CVE-2023-27320 Sudo before 1.9.13p2 has a double free in the per-command chroot feature.

Version: 1.9.9-1ubuntu2.2 2023-01-18 20:08:16 UTC

  sudo (1.9.9-1ubuntu2.2) jammy-security; urgency=medium

  * SECURITY UPDATE: arbitrary file overwrite via sudoedit
    - debian/patches/CVE-2023-22809.patch: do not permit editor arguments
      to include -- in plugins/sudoers/editor.c, plugins/sudoers/sudoers.c,
      plugins/sudoers/visudo.c.
    - CVE-2023-22809
  * SECURITY UPDATE: DoS via invalid arithmetic shift in Protobuf-c
    - debian/patches/CVE-2022-33070.patch: only shift unsigned values in
      lib/protobuf-c/protobuf-c.c.
    - CVE-2022-33070

 -- Marc Deslauriers <email address hidden> Mon, 16 Jan 2023 07:36:33 -0500

CVE-2022-33070 Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vuln



About   -   Send Feedback to @ubuntu_updates