Publishing details

Changelog

sudo (1.8.9p5-1ubuntu1.4tarent1) trusty; urgency=high

  * Non-maintainer upload.
  * Merge sudo (1.8.10p3-1+deb8u8) jessie-security; urgency=medium

  [ Thorsten Alteholz ]
  * Non-maintainer upload by the ELTS Team.
  * Heap-based buffer overflow (CVE-2021-3156)
    (based on patches provided by Salvatore for Stretch)
    - Reset valid_flags to MODE_NONINTERACTIVE for sudoedit
    - Add sudoedit flag checks in plugin that are consistent with front-end
    - Fix potential buffer overflow when unescaping backslashes in user_args
    - Don't assume that argv is allocated as a single flat buffer

 -- Thorsten Glaser <email address hidden>  Wed, 27 Jan 2021 23:05:33 +0100

Available diffs

Builds

Built packages

Package files