Format: 1.8 Date: Tue, 19 Jan 2021 09:21:02 -0500 Source: sudo Binary: sudo sudo-ldap Architecture: amd64 amd64_translations Version: 1.8.31-1ubuntu1.2 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: sudo - Provide limited super user privileges to specific users sudo-ldap - Provide limited super user privileges to specific users Changes: sudo (1.8.31-1ubuntu1.2) focal-security; urgency=medium . * SECURITY UPDATE: dir existence issue via sudoedit race - debian/patches/CVE-2021-23239.patch: fix potential directory existing info leak in sudoedit in src/sudo_edit.c. - CVE-2021-23239 * SECURITY UPDATE: heap-based buffer overflow - debian/patches/CVE-2021-3156-pre1.patch: sanity check size when converting the first record to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-1.patch: reset valid_flags to MODE_NONINTERACTIVE for sudoedit in src/parse_args.c. - debian/patches/CVE-2021-3156-2.patch: add sudoedit flag checks in plugin in plugins/sudoers/policy.c. - debian/patches/CVE-2021-3156-3.patch: fix potential buffer overflow when unescaping backslashes in plugins/sudoers/sudoers.c. - debian/patches/CVE-2021-3156-4.patch: fix the memset offset when converting a v1 timestamp to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-5.patch: don't assume that argv is allocated as a single flat buffer in src/parse_args.c. - CVE-2021-3156 Checksums-Sha1: f907341e3b7771a11cd58bd73fa70f2707b44866 1274764 sudo-dbgsym_1.8.31-1ubuntu1.2_amd64.ddeb d4d302a8251cae4c320f827ab99d6753b7c77aa4 1323516 sudo-ldap-dbgsym_1.8.31-1ubuntu1.2_amd64.ddeb 6fb30029d194da196a803db3485d194753157e43 550520 sudo-ldap_1.8.31-1ubuntu1.2_amd64.deb 13eaf37c1af23cd482f87a611073a2f05e67157b 7513 sudo_1.8.31-1ubuntu1.2_amd64.buildinfo b1acab1d32ea66059e109ff2f0e2f8a584f8ee1b 514496 sudo_1.8.31-1ubuntu1.2_amd64.deb ee115ff84100e998833316bd71d055ba9e5e6817 2097272 sudo_1.8.31-1ubuntu1.2_amd64_translations.tar.gz Checksums-Sha256: cecda93c6cb51c3e92cdc2abb1dd7ddc5dcca84cace20616839001c4a6d2cd39 1274764 sudo-dbgsym_1.8.31-1ubuntu1.2_amd64.ddeb 47faacf1285edf8e52ab3365a91a0e255f2d5343e1c98bb012fcb7fb1b95fd7d 1323516 sudo-ldap-dbgsym_1.8.31-1ubuntu1.2_amd64.ddeb f7ead8c5b02289e0992c57659a5a51093b89ece6888f88f70dc9c241a8c4afb6 550520 sudo-ldap_1.8.31-1ubuntu1.2_amd64.deb 1db5b834f2f93e4083670ab98cfb22d25bd0866bebe6a67c862c4c12aa61b325 7513 sudo_1.8.31-1ubuntu1.2_amd64.buildinfo 299ba24c67170a613033708418f3ba05147b32fe12688355e5d17de72b702222 514496 sudo_1.8.31-1ubuntu1.2_amd64.deb 88edfdd4bb99f0f29fcd8b3075f09fb80d89996071ae6ee9aad6039c8527dd41 2097272 sudo_1.8.31-1ubuntu1.2_amd64_translations.tar.gz Files: 05c9f2c39a6a7270c108cf5ba2ac38bc 1274764 debug optional sudo-dbgsym_1.8.31-1ubuntu1.2_amd64.ddeb 8fa6003c01f78363305c41021e2e5406 1323516 debug optional sudo-ldap-dbgsym_1.8.31-1ubuntu1.2_amd64.ddeb 001982976df45d8cc0cb40c58f5ec06e 550520 admin optional sudo-ldap_1.8.31-1ubuntu1.2_amd64.deb 551a53682c86ffe94b96179b03417998 7513 admin optional sudo_1.8.31-1ubuntu1.2_amd64.buildinfo 2c6a4ec3b445662f2b7f4750a2a3d816 514496 admin optional sudo_1.8.31-1ubuntu1.2_amd64.deb 2c87704ae824d59e4820eacd80115e6e 2097272 raw-translations - sudo_1.8.31-1ubuntu1.2_amd64_translations.tar.gz Original-Maintainer: Bdale Garbee