Format: 1.8 Date: Tue, 19 Jan 2021 09:48:09 -0500 Source: sudo Binary: sudo sudo-ldap Architecture: powerpc powerpc_translations Version: 1.8.16-0ubuntu1.10 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: sudo - Provide limited super user privileges to specific users sudo-ldap - Provide limited super user privileges to specific users Changes: sudo (1.8.16-0ubuntu1.10) xenial-security; urgency=medium . * SECURITY UPDATE: dir existence issue via sudoedit race - debian/patches/CVE-2021-23239.patch: fix potential directory existing info leak in sudoedit in src/sudo_edit.c. - CVE-2021-23239 * SECURITY UPDATE: heap-based buffer overflow - debian/patches/CVE-2021-3156-pre1.patch: check lock record size in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-pre2.patch: sanity check size when converting the first record to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-1.patch: reset valid_flags to MODE_NONINTERACTIVE for sudoedit in src/parse_args.c. - debian/patches/CVE-2021-3156-2.patch: add sudoedit flag checks in plugin in plugins/sudoers/policy.c. - debian/patches/CVE-2021-3156-3.patch: fix potential buffer overflow when unescaping backslashes in plugins/sudoers/sudoers.c. - debian/patches/CVE-2021-3156-4.patch: fix the memset offset when converting a v1 timestamp to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-5.patch: don't assume that argv is allocated as a single flat buffer in src/parse_args.c. - CVE-2021-3156 Checksums-Sha1: 906a45f4fb9dc8ed63d5d0ae954f83d7c66e2f14 434514 sudo-dbgsym_1.8.16-0ubuntu1.10_powerpc.ddeb 1c0c548e3073d852cb9c2a5f0eb62e80cb9503f4 450632 sudo-ldap-dbgsym_1.8.16-0ubuntu1.10_powerpc.ddeb 234bfb4d079998b5f304cc536d32f3c632693d81 373798 sudo-ldap_1.8.16-0ubuntu1.10_powerpc.deb 016bd2c0dd495a955ffc9a162cc5031672d2d3e7 345858 sudo_1.8.16-0ubuntu1.10_powerpc.deb 6ef65f6ba83c3aff1ad95e83f9de8940e34a6da1 1438569 sudo_1.8.16-0ubuntu1.10_powerpc_translations.tar.gz Checksums-Sha256: a7e37f9d2311280022151c41bd7bb688ce94e9e6645becf306b64a963551839e 434514 sudo-dbgsym_1.8.16-0ubuntu1.10_powerpc.ddeb 857df7fb8be81d0e9b94bc447205fcbd8e03879e3af9f695ce0fb3f0195065c6 450632 sudo-ldap-dbgsym_1.8.16-0ubuntu1.10_powerpc.ddeb b18b40d8f04b3e012d29e37182e386b2702ed943e6c75c49d302a8394dece2d9 373798 sudo-ldap_1.8.16-0ubuntu1.10_powerpc.deb f467080a0dc4be704b94e957952619448b113155bd9332e655d2147ba9d02985 345858 sudo_1.8.16-0ubuntu1.10_powerpc.deb 7d60d511e7f38544df4c7af37590f95f7e0eaa7ef7f2cfe51632fa80d71d146d 1438569 sudo_1.8.16-0ubuntu1.10_powerpc_translations.tar.gz Files: a825a4b2fc6de9fa82f133edbee99fa8 434514 admin extra sudo-dbgsym_1.8.16-0ubuntu1.10_powerpc.ddeb f2740608e2436b5db6ee383d113acade 450632 admin extra sudo-ldap-dbgsym_1.8.16-0ubuntu1.10_powerpc.ddeb 13607bd5f8efbbf21d7f772de75a4ecb 373798 admin optional sudo-ldap_1.8.16-0ubuntu1.10_powerpc.deb 24804089ef956a390eaeb600429d7f41 345858 admin optional sudo_1.8.16-0ubuntu1.10_powerpc.deb 4678ce354cad02357e5198597356298c 1438569 raw-translations - sudo_1.8.16-0ubuntu1.10_powerpc_translations.tar.gz Original-Maintainer: Bdale Garbee