UbuntuUpdates.org

Package "sudo-ldap"

Name: sudo-ldap

Description:

Provide limited super user privileges to specific users

Latest version: 1.8.3p1-1ubuntu3.10
Release: precise (12.04)
Level: updates
Repository: universe
Head package: sudo

Links


Download "sudo-ldap"


Other versions of "sudo-ldap" in Precise

Repository Area Version
base universe 1.8.3p1-1ubuntu3
security universe 1.8.3p1-1ubuntu3.10

Changelog

Version: 1.8.3p1-1ubuntu3.10 2021-05-03 16:06:23 UTC

  sudo (1.8.3p1-1ubuntu3.10) precise-security; urgency=medium

  * SECURITY UPDATE: heap-based buffer overflow
    - debian/patches/CVE-2021-3156-1.patch: reset valid_flags to
      MODE_NONINTERACTIVE for sudoedit in src/parse_args.c.
    - debian/patches/CVE-2021-3156-2.patch: add sudoedit flag checks in
      plugin in plugins/sudoers/sudoers.c.
    - debian/patches/CVE-2021-3156-3.patch: fix potential buffer overflow
      when unescaping backslashes in plugins/sudoers/sudoers.c.
    - debian/patches/CVE-2021-3156-5.patch: don't assume that argv is
      allocated as a single flat buffer in src/parse_args.c.
    - CVE-2021-3156

 -- Leonidas Da Silva Barbosa <email address hidden> Wed, 27 Jan 2021 08:49:33 -0300

Source diff to previous version
CVE-2021-3156 Heap-based buffer overflow

Version: 1.8.3p1-1ubuntu3.7 2015-03-16 15:07:30 UTC

  sudo (1.8.3p1-1ubuntu3.7) precise-security; urgency=medium

  * SECURITY UPDATE: arbitrary file access via TZ
    - debian/patches/CVE-2014-9680.patch: sanity check TZ env variable in
      configure, configure.in, doc/sudoers.cat, doc/sudoers.man.in,
      pathnames.h.in, plugins/sudoers/env.c.
    - CVE-2014-9680
 -- Marc Deslauriers <email address hidden> Thu, 12 Mar 2015 11:32:42 -0400

Source diff to previous version
CVE-2014-9680 preserves TZ by default

Version: 1.8.3p1-1ubuntu3.6 2014-03-13 16:07:18 UTC

  sudo (1.8.3p1-1ubuntu3.6) precise-security; urgency=medium

  * SECURITY UPDATE: security policy bypass when env_reset is disabled
    - debian/patches/CVE-2014-0106.patch: fix logic inversion in
      plugins/sudoers/env.c.
    - CVE-2014-0106
  * debian/sudo.sudo.init, debian/sudo-ldap.sudo.init: Set timestamps to
    epoch in init scripts so they are properly invalidated. (LP: #1223297)
 -- Marc Deslauriers <email address hidden> Tue, 11 Mar 2014 07:56:53 -0400

Source diff to previous version
1223297 sudo init script should set date to epoch, not 1985-01-01

Version: 1.8.3p1-1ubuntu3.4 2013-02-28 15:06:44 UTC

  sudo (1.8.3p1-1ubuntu3.4) precise-security; urgency=low

  * SECURITY UPDATE: authentication bypass via clock set to epoch
    - debian/patches/CVE-2013-1775.patch: ignore time stamp file if it is
      set to epoch in plugins/sudoers/check.c.
    - CVE-2013-1775
 -- Marc Deslauriers <email address hidden> Wed, 27 Feb 2013 13:34:15 -0500

Source diff to previous version

Version: 1.8.3p1-1ubuntu3.3 2012-06-08 13:06:45 UTC

  sudo (1.8.3p1-1ubuntu3.3) precise-proposed; urgency=low

  * debian/patches/pam_env_merge.patch: Merge the PAM environment into the
    user environment (LP: #982684)
  * debian/sudo.pam: Use pam_env to read /etc/environment and
    /etc/default/locale environment files. Reading ~/.pam_environment is not
    permitted due to security reasons.
 -- Tyler Hicks <email address hidden> Mon, 21 May 2012 00:48:10 -0500

982684 sudo, pkexec don't apply global environment setting...



About   -   Send Feedback to @ubuntu_updates