Format: 1.8 Date: Tue, 19 Jan 2021 09:48:09 -0500 Source: sudo Binary: sudo sudo-ldap Architecture: i386 i386_translations Version: 1.8.16-0ubuntu1.10 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: sudo - Provide limited super user privileges to specific users sudo-ldap - Provide limited super user privileges to specific users Changes: sudo (1.8.16-0ubuntu1.10) xenial-security; urgency=medium . * SECURITY UPDATE: dir existence issue via sudoedit race - debian/patches/CVE-2021-23239.patch: fix potential directory existing info leak in sudoedit in src/sudo_edit.c. - CVE-2021-23239 * SECURITY UPDATE: heap-based buffer overflow - debian/patches/CVE-2021-3156-pre1.patch: check lock record size in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-pre2.patch: sanity check size when converting the first record to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-1.patch: reset valid_flags to MODE_NONINTERACTIVE for sudoedit in src/parse_args.c. - debian/patches/CVE-2021-3156-2.patch: add sudoedit flag checks in plugin in plugins/sudoers/policy.c. - debian/patches/CVE-2021-3156-3.patch: fix potential buffer overflow when unescaping backslashes in plugins/sudoers/sudoers.c. - debian/patches/CVE-2021-3156-4.patch: fix the memset offset when converting a v1 timestamp to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-5.patch: don't assume that argv is allocated as a single flat buffer in src/parse_args.c. - CVE-2021-3156 Checksums-Sha1: e170770db98ee47e163bed87ebd7f48bdde95440 384458 sudo-dbgsym_1.8.16-0ubuntu1.10_i386.ddeb 07a9dfe5dfc13c4911a5606dab5c1525f8a3da66 400104 sudo-ldap-dbgsym_1.8.16-0ubuntu1.10_i386.ddeb ed40087494967118524a136e4977d6aaa27baf3f 425218 sudo-ldap_1.8.16-0ubuntu1.10_i386.deb d3747656258145d079ee5ab27193aabfa37ec990 395984 sudo_1.8.16-0ubuntu1.10_i386.deb 49aa51955eb1e877dab1cd40a040992e18bc743d 1456136 sudo_1.8.16-0ubuntu1.10_i386_translations.tar.gz Checksums-Sha256: 66ee325a9cfad0976a5a09b6b78153f1c9fc08f058b92c8e71b5073a5b75ea21 384458 sudo-dbgsym_1.8.16-0ubuntu1.10_i386.ddeb 9e02695fbe43437f3c1bd29e3e02ba2845bbc18781903cefcf74da93b8db6374 400104 sudo-ldap-dbgsym_1.8.16-0ubuntu1.10_i386.ddeb 65030e09b6949b8608f7147db7dd386229721b96c8e5d0c72f3f075c7c5d0123 425218 sudo-ldap_1.8.16-0ubuntu1.10_i386.deb 00eb0180e6d90f1b66b548bf806270be732ac6e10778dc3170dd26476f074e29 395984 sudo_1.8.16-0ubuntu1.10_i386.deb c5289a8af382ef1a5206db3a5018d5f0e183f3dc1102d3be25e3dfae16eee64d 1456136 sudo_1.8.16-0ubuntu1.10_i386_translations.tar.gz Files: d2254b4ab0c8ef74ebce8c0af31f2116 384458 admin extra sudo-dbgsym_1.8.16-0ubuntu1.10_i386.ddeb 79fa9b5f992f1aaaa54dd1481b6e686a 400104 admin extra sudo-ldap-dbgsym_1.8.16-0ubuntu1.10_i386.ddeb 7793ec12e085c40f59a196ac56f72712 425218 admin optional sudo-ldap_1.8.16-0ubuntu1.10_i386.deb a59f71c01d8b13f498ea5f6f8c9b9ebb 395984 admin optional sudo_1.8.16-0ubuntu1.10_i386.deb 02b3d4bf486e15da3980067a7ee87e05 1456136 raw-translations - sudo_1.8.16-0ubuntu1.10_i386_translations.tar.gz Original-Maintainer: Bdale Garbee