Format: 1.8 Date: Tue, 19 Jan 2021 09:21:02 -0500 Source: sudo Binary: sudo sudo-ldap Architecture: ppc64el ppc64el_translations Version: 1.8.31-1ubuntu1.2 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: sudo - Provide limited super user privileges to specific users sudo-ldap - Provide limited super user privileges to specific users Changes: sudo (1.8.31-1ubuntu1.2) focal-security; urgency=medium . * SECURITY UPDATE: dir existence issue via sudoedit race - debian/patches/CVE-2021-23239.patch: fix potential directory existing info leak in sudoedit in src/sudo_edit.c. - CVE-2021-23239 * SECURITY UPDATE: heap-based buffer overflow - debian/patches/CVE-2021-3156-pre1.patch: sanity check size when converting the first record to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-1.patch: reset valid_flags to MODE_NONINTERACTIVE for sudoedit in src/parse_args.c. - debian/patches/CVE-2021-3156-2.patch: add sudoedit flag checks in plugin in plugins/sudoers/policy.c. - debian/patches/CVE-2021-3156-3.patch: fix potential buffer overflow when unescaping backslashes in plugins/sudoers/sudoers.c. - debian/patches/CVE-2021-3156-4.patch: fix the memset offset when converting a v1 timestamp to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-5.patch: don't assume that argv is allocated as a single flat buffer in src/parse_args.c. - CVE-2021-3156 Checksums-Sha1: 3ee2f598db556966b95fea96a9795a6dff18f73f 1376044 sudo-dbgsym_1.8.31-1ubuntu1.2_ppc64el.ddeb 9eda8858b28c9784b5ffe3067ba1786401e04f5a 1429044 sudo-ldap-dbgsym_1.8.31-1ubuntu1.2_ppc64el.ddeb 959637ed67887d350e9f9fc867d21d0a0a3bac1e 542952 sudo-ldap_1.8.31-1ubuntu1.2_ppc64el.deb 17fa542cfb519f7f16ac863b6afa3877d9a823a2 7552 sudo_1.8.31-1ubuntu1.2_ppc64el.buildinfo dadc258c3f5309deb6e551ef7611e69559ef0021 508008 sudo_1.8.31-1ubuntu1.2_ppc64el.deb 198c2014896c3ab78281e399bd5323e9b9479a45 2090217 sudo_1.8.31-1ubuntu1.2_ppc64el_translations.tar.gz Checksums-Sha256: e9de7f805b3dbca4f5261da287f64e5e27b8f15fb343c8def52e7aa8af84af8a 1376044 sudo-dbgsym_1.8.31-1ubuntu1.2_ppc64el.ddeb ddcb1c5556270533ad0087e7bc10ccfca2a10f8680aa790d18555ecb27d9802d 1429044 sudo-ldap-dbgsym_1.8.31-1ubuntu1.2_ppc64el.ddeb 2bbe87c849b4461d1734fc510f124b3dbbd84f5793fc0af31ae22d4123c9420b 542952 sudo-ldap_1.8.31-1ubuntu1.2_ppc64el.deb 93999be6c8c38139efc74d84a987b831a6857a2c8206a48be07a95592e0bfc16 7552 sudo_1.8.31-1ubuntu1.2_ppc64el.buildinfo 4e9d4af95171391bebab6fc07a605c4024ce6c92d4f2cc0d86eec446f7e43972 508008 sudo_1.8.31-1ubuntu1.2_ppc64el.deb 4b7ea46c0c41f37ae478925fa3ecce90e048725ee5c082aca1fc28e5dc37f0f5 2090217 sudo_1.8.31-1ubuntu1.2_ppc64el_translations.tar.gz Files: 5212ac6256b5ba386e91f226af59e7ad 1376044 debug optional sudo-dbgsym_1.8.31-1ubuntu1.2_ppc64el.ddeb 62a62799918450fe641d50469bf4c973 1429044 debug optional sudo-ldap-dbgsym_1.8.31-1ubuntu1.2_ppc64el.ddeb b81c53ff38c291c9e42e85877bbf7d8c 542952 admin optional sudo-ldap_1.8.31-1ubuntu1.2_ppc64el.deb 7054de81096213f32a1db498939386c8 7552 admin optional sudo_1.8.31-1ubuntu1.2_ppc64el.buildinfo e464f2be012cff663c8fdddf4aebf4c2 508008 admin optional sudo_1.8.31-1ubuntu1.2_ppc64el.deb 3307ae510cd4cc05bd9f789e525769bb 2090217 raw-translations - sudo_1.8.31-1ubuntu1.2_ppc64el_translations.tar.gz Original-Maintainer: Bdale Garbee