sudo does not check fdqn properly

Bug #1451274 reported by David Zanetti
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
sudo
Unknown
Unknown
sudo (Debian)
Fix Released
Unknown
sudo (Ubuntu)
Fix Released
Medium
Unassigned
Trusty
Triaged
Medium
Unassigned
Utopic
Won't Fix
Medium
Unassigned
Vivid
Won't Fix
Medium
Unassigned

Bug Description

As noted in https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731583, from sudo 1.8.8 it does not correctly check fqdn for sudoers entries that contain FQDN hostnames, or netgroups which contain FQDN entries (which is fairly common, eg when using hostgroups with FreeIPA).

There is an upstream fix available (as noted on the Debian bug report) which does resolve this problem. It does not appear to have been applied to sudo as of 14.04.2 at least.

Related branches

Changed in sudo (Ubuntu Trusty):
status: New → Confirmed
Changed in sudo (Ubuntu Utopic):
status: New → Confirmed
Changed in sudo (Ubuntu Vivid):
status: New → Confirmed
Changed in sudo:
status: Unknown → Fix Released
Revision history for this message
Brian Murray (brian-murray) wrote :

Fixed in this debian version

Source: sudo
Source-Version: 1.8.10p3-1+deb8u1

Changed in sudo (Ubuntu):
status: Confirmed → Triaged
Changed in sudo (Ubuntu Trusty):
status: Confirmed → Triaged
Changed in sudo (Ubuntu Utopic):
status: Confirmed → Triaged
Changed in sudo (Ubuntu Vivid):
status: Confirmed → Triaged
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package sudo - 1.8.12-1ubuntu1

---------------
sudo (1.8.12-1ubuntu1) wily; urgency=medium

  * Merge from Debian unstable. (LP: #1451274, LP: #1219337)
    Remaining changes:
    - debian/rules:
      + compile with --without-lecture --with-tty-tickets --enable-admin-flag
      + install man/man8/sudo_root.8 in both flavours
      + install apport hooks
    - debian/sudoers:
      + also grant admin group sudo access
    - debian/source_sudo.py, debian/sudo-ldap.dirs, debian/sudo.dirs:
      + add usr/share/apport/package-hooks
    - debian/sudo.pam:
      + Use pam_env to read /etc/environment and /etc/default/locale
        environment files. Reading ~/.pam_environment is not permitted due to
        security reasons.
    - debian/control:
      + dh-autoreconf dependency fixes missing-build-dependency-for-dh_-command
    - Remaining patches:
      + keep_home_by_default.patch: Keep HOME in the default environment
      + debian/patches/also_check_sudo_group.diff: also check the sudo group
        in plugins/sudoers/sudoers.c to create the admin flag file. Leave the
        admin group check for backwards compatibility.
  * Dropped patches no longer needed:
      + add_probe_interfaces_setting.diff
      + actually-use-buildflags.diff
      + CVE-2014-9680.patch

sudo (1.8.12-1) unstable; urgency=low

  * new upstream version, closes: #772707, #773383
  * patch from Christian Kastner to fix sudoers handling error when moving
    between sudo and sudo-ldap packages, closes: #776137

sudo (1.8.11p2-1) unstable; urgency=low

  * new upstream version

sudo (1.8.11p1-2) unstable; urgency=low

  * patch from Jakub Wilk to fix 'ignoring time stamp from the future'
    messages, closes: #762465
  * upstream patch forwarded by Laurent Bigonville that fixes problem with
    Linux kernel auditing code, closes: #764817

sudo (1.8.11p1-1) unstable; urgency=low

  * new upstream version, closes: #764286
  * fix typo in German translation, closes: #761601

sudo (1.8.10p3-1) unstable; urgency=low

  * new upstream release
  * add hardening=+all to match login and su
  * updated VCS URLs and crypto verified watch file, closes: #747473
  * harmonize configure options for LDAP version to match non-LDAP version,
    in particular stop using --with-secure-path and add configure_args
  * enable audit support on Linux systems, closes: #745779
  * follow upstream change from --with-timedir to --with-rundir

 -- Marc Deslauriers <email address hidden> Wed, 13 May 2015 15:43:49 -0400

Changed in sudo (Ubuntu):
status: Triaged → Fix Released
Mathew Hodson (mhodson)
Changed in sudo:
status: Fix Released → Unknown
Changed in sudo (Ubuntu):
importance: Undecided → Medium
Changed in sudo (Ubuntu Trusty):
importance: Undecided → Medium
Changed in sudo (Ubuntu Vivid):
importance: Undecided → Medium
Changed in sudo (Ubuntu Utopic):
importance: Undecided → Medium
status: Triaged → Won't Fix
Changed in sudo (Ubuntu Vivid):
status: Triaged → Won't Fix
Changed in sudo (Debian):
status: Unknown → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.