Format: 1.8 Date: Tue, 19 Jan 2021 09:48:09 -0500 Source: sudo Binary: sudo sudo-ldap Architecture: armhf armhf_translations Version: 1.8.16-0ubuntu1.10 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: sudo - Provide limited super user privileges to specific users sudo-ldap - Provide limited super user privileges to specific users Changes: sudo (1.8.16-0ubuntu1.10) xenial-security; urgency=medium . * SECURITY UPDATE: dir existence issue via sudoedit race - debian/patches/CVE-2021-23239.patch: fix potential directory existing info leak in sudoedit in src/sudo_edit.c. - CVE-2021-23239 * SECURITY UPDATE: heap-based buffer overflow - debian/patches/CVE-2021-3156-pre1.patch: check lock record size in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-pre2.patch: sanity check size when converting the first record to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-1.patch: reset valid_flags to MODE_NONINTERACTIVE for sudoedit in src/parse_args.c. - debian/patches/CVE-2021-3156-2.patch: add sudoedit flag checks in plugin in plugins/sudoers/policy.c. - debian/patches/CVE-2021-3156-3.patch: fix potential buffer overflow when unescaping backslashes in plugins/sudoers/sudoers.c. - debian/patches/CVE-2021-3156-4.patch: fix the memset offset when converting a v1 timestamp to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-5.patch: don't assume that argv is allocated as a single flat buffer in src/parse_args.c. - CVE-2021-3156 Checksums-Sha1: bb8a65aea377f403443339d8ed33dd51ba26d7e1 438288 sudo-dbgsym_1.8.16-0ubuntu1.10_armhf.ddeb 21f872fd3781bac5d2d2202dd9c7d855b388ddc9 455486 sudo-ldap-dbgsym_1.8.16-0ubuntu1.10_armhf.ddeb ad9b32bb6e7a29f0a61706a891668813e7fa06a1 401298 sudo-ldap_1.8.16-0ubuntu1.10_armhf.deb e22514c451899dfdec5244930513720a1d53a6e5 370804 sudo_1.8.16-0ubuntu1.10_armhf.deb 605b894691dac5e001fb87062a61940751af006c 1445179 sudo_1.8.16-0ubuntu1.10_armhf_translations.tar.gz Checksums-Sha256: f059849d5b2809b7a56828324f23a2d31e1468af9ca357651db16c15897d670b 438288 sudo-dbgsym_1.8.16-0ubuntu1.10_armhf.ddeb dd68b3a9f3dd3060ff9d66115fefbda1b722aba105437d24693f09849676e51b 455486 sudo-ldap-dbgsym_1.8.16-0ubuntu1.10_armhf.ddeb 4da5f72dab9de0cbf9bdf50e433d09e1b672e79be41b1cac6304abbc5ea9df2f 401298 sudo-ldap_1.8.16-0ubuntu1.10_armhf.deb 63807358c6ef7d7299ef5cd91a52ed4945667696773581ca19af7cd02c78de28 370804 sudo_1.8.16-0ubuntu1.10_armhf.deb 8eac6f856771ff70ff34e76d374949792f419b89a8aa92f3c15c85cf273d5467 1445179 sudo_1.8.16-0ubuntu1.10_armhf_translations.tar.gz Files: 3b850fe9e6624f7c35c517da81226494 438288 admin extra sudo-dbgsym_1.8.16-0ubuntu1.10_armhf.ddeb 7a3464d78388db7af5ee588908134437 455486 admin extra sudo-ldap-dbgsym_1.8.16-0ubuntu1.10_armhf.ddeb db4bf5eaf6a0e9edb7e0972983ad2372 401298 admin optional sudo-ldap_1.8.16-0ubuntu1.10_armhf.deb bde21601d8cfd706bca744cc6b95d4b2 370804 admin optional sudo_1.8.16-0ubuntu1.10_armhf.deb 2123716066b5bc02adbcd54d81451e69 1445179 raw-translations - sudo_1.8.16-0ubuntu1.10_armhf_translations.tar.gz Original-Maintainer: Bdale Garbee