Format: 1.8 Date: Tue, 19 Jan 2021 09:48:09 -0500 Source: sudo Binary: sudo sudo-ldap Architecture: ppc64el ppc64el_translations Version: 1.8.16-0ubuntu1.10 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: sudo - Provide limited super user privileges to specific users sudo-ldap - Provide limited super user privileges to specific users Changes: sudo (1.8.16-0ubuntu1.10) xenial-security; urgency=medium . * SECURITY UPDATE: dir existence issue via sudoedit race - debian/patches/CVE-2021-23239.patch: fix potential directory existing info leak in sudoedit in src/sudo_edit.c. - CVE-2021-23239 * SECURITY UPDATE: heap-based buffer overflow - debian/patches/CVE-2021-3156-pre1.patch: check lock record size in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-pre2.patch: sanity check size when converting the first record to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-1.patch: reset valid_flags to MODE_NONINTERACTIVE for sudoedit in src/parse_args.c. - debian/patches/CVE-2021-3156-2.patch: add sudoedit flag checks in plugin in plugins/sudoers/policy.c. - debian/patches/CVE-2021-3156-3.patch: fix potential buffer overflow when unescaping backslashes in plugins/sudoers/sudoers.c. - debian/patches/CVE-2021-3156-4.patch: fix the memset offset when converting a v1 timestamp to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-5.patch: don't assume that argv is allocated as a single flat buffer in src/parse_args.c. - CVE-2021-3156 Checksums-Sha1: 0bc72fe15665a28c801594f83ad3453eca30d859 500882 sudo-dbgsym_1.8.16-0ubuntu1.10_ppc64el.ddeb e9a604f9b28ba23fd7787132f6ccc6d69e78e401 519526 sudo-ldap-dbgsym_1.8.16-0ubuntu1.10_ppc64el.ddeb b4b18d8c155c8affaf9269d32f2424302bcd67fa 396066 sudo-ldap_1.8.16-0ubuntu1.10_ppc64el.deb 4880511631f1b04ac88e1b305ee4e2428910fbdc 366768 sudo_1.8.16-0ubuntu1.10_ppc64el.deb 7100d6f356913c4bd349190bc74ef1fcf2914550 1454122 sudo_1.8.16-0ubuntu1.10_ppc64el_translations.tar.gz Checksums-Sha256: da690024299cf066133a978cd59e3ff00c059518fee52cef9198dc09bd38fca8 500882 sudo-dbgsym_1.8.16-0ubuntu1.10_ppc64el.ddeb 5e6d14a760241f80e1f6168361cfe2be9c6d7dbdd9743a6cd5ca72c9dc0ff253 519526 sudo-ldap-dbgsym_1.8.16-0ubuntu1.10_ppc64el.ddeb 39657074a8458570c23b73b4f5d8d8c2577420f5eea45ae0b86321e65ce90c0b 396066 sudo-ldap_1.8.16-0ubuntu1.10_ppc64el.deb db8dd3e48fb4ef65532dd193817f9843e74de088520bba034d21b0ff6f79a3cf 366768 sudo_1.8.16-0ubuntu1.10_ppc64el.deb c812d02af8f9942205d06e099168e1ef9b3bb838e2bcc8f3d85a803233719af0 1454122 sudo_1.8.16-0ubuntu1.10_ppc64el_translations.tar.gz Files: 68d404412054d1badf5128f143190f14 500882 admin extra sudo-dbgsym_1.8.16-0ubuntu1.10_ppc64el.ddeb 38c68f8c341ee5c5347dba506198dfc0 519526 admin extra sudo-ldap-dbgsym_1.8.16-0ubuntu1.10_ppc64el.ddeb ef28cdb1718f8e7edb94b8a3115ea69f 396066 admin optional sudo-ldap_1.8.16-0ubuntu1.10_ppc64el.deb c57970893df31cffb164ea57370232e6 366768 admin optional sudo_1.8.16-0ubuntu1.10_ppc64el.deb a00fa81cdca20951556176913bcc88ba 1454122 raw-translations - sudo_1.8.16-0ubuntu1.10_ppc64el_translations.tar.gz Original-Maintainer: Bdale Garbee