Format: 1.8 Date: Tue, 19 Jan 2021 09:21:02 -0500 Source: sudo Binary: sudo sudo-ldap Architecture: armhf armhf_translations Version: 1.8.31-1ubuntu1.2 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: sudo - Provide limited super user privileges to specific users sudo-ldap - Provide limited super user privileges to specific users Changes: sudo (1.8.31-1ubuntu1.2) focal-security; urgency=medium . * SECURITY UPDATE: dir existence issue via sudoedit race - debian/patches/CVE-2021-23239.patch: fix potential directory existing info leak in sudoedit in src/sudo_edit.c. - CVE-2021-23239 * SECURITY UPDATE: heap-based buffer overflow - debian/patches/CVE-2021-3156-pre1.patch: sanity check size when converting the first record to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-1.patch: reset valid_flags to MODE_NONINTERACTIVE for sudoedit in src/parse_args.c. - debian/patches/CVE-2021-3156-2.patch: add sudoedit flag checks in plugin in plugins/sudoers/policy.c. - debian/patches/CVE-2021-3156-3.patch: fix potential buffer overflow when unescaping backslashes in plugins/sudoers/sudoers.c. - debian/patches/CVE-2021-3156-4.patch: fix the memset offset when converting a v1 timestamp to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-5.patch: don't assume that argv is allocated as a single flat buffer in src/parse_args.c. - CVE-2021-3156 Checksums-Sha1: a79ac44d643d5aeff940ae0905553f5c1999ce78 1257476 sudo-dbgsym_1.8.31-1ubuntu1.2_armhf.ddeb 487afff44c702c952618ffd34b7b8a878a630b71 1303012 sudo-ldap-dbgsym_1.8.31-1ubuntu1.2_armhf.ddeb 43e9997db55784a19a84a7f1040e7c67ce12425d 515364 sudo-ldap_1.8.31-1ubuntu1.2_armhf.deb 12a2933f00bb06a4b82d0e667ad82f0474f6c583 7365 sudo_1.8.31-1ubuntu1.2_armhf.buildinfo 2dc32babed5f688b2380b40999c4ef7ae9fe7f36 479768 sudo_1.8.31-1ubuntu1.2_armhf.deb 3c8b67be57bbe54dca997a4046f30a0f77fa5924 2068081 sudo_1.8.31-1ubuntu1.2_armhf_translations.tar.gz Checksums-Sha256: 3dbb8ed6373b05654f8dcd33556a6514c498639fccb36ac331574186f31309b6 1257476 sudo-dbgsym_1.8.31-1ubuntu1.2_armhf.ddeb 8df3a9b5c55a4619ae5cc136ee5fdc5bf463c59b62d37fff66e7c1801465ea51 1303012 sudo-ldap-dbgsym_1.8.31-1ubuntu1.2_armhf.ddeb 4b08a391ee735711f24a566729ec6a09b5ca1f1cbea992f3011e29d681bc3406 515364 sudo-ldap_1.8.31-1ubuntu1.2_armhf.deb 1f14a6fef3a98600e3a5c61ffbd71b1900af9ad8e12fc37468436bb1645e50f4 7365 sudo_1.8.31-1ubuntu1.2_armhf.buildinfo 0d87b74312bfae30f73579304a386d86672fd3d8799e2c1bad70363949d3bc1b 479768 sudo_1.8.31-1ubuntu1.2_armhf.deb 334101cd5f6fb828f8f226c9597217ed7ceec2da4d0760a960838b65e9ab2a1e 2068081 sudo_1.8.31-1ubuntu1.2_armhf_translations.tar.gz Files: c8b8dcdc4ebe2dc2d59aaa0f6eb7770e 1257476 debug optional sudo-dbgsym_1.8.31-1ubuntu1.2_armhf.ddeb 7d7f2f3cb9c93e79f6c28fca9715ba3f 1303012 debug optional sudo-ldap-dbgsym_1.8.31-1ubuntu1.2_armhf.ddeb 7ac1ae609cdd2d4ad12b0307a8738e65 515364 admin optional sudo-ldap_1.8.31-1ubuntu1.2_armhf.deb 756f3a14a9e6657891fb42fb51f6ad40 7365 admin optional sudo_1.8.31-1ubuntu1.2_armhf.buildinfo 91b13503e7098dcd81976e74e234e81f 479768 admin optional sudo_1.8.31-1ubuntu1.2_armhf.deb c84f4b9c6ec036a1f9e0e18692557531 2068081 raw-translations - sudo_1.8.31-1ubuntu1.2_armhf_translations.tar.gz Original-Maintainer: Bdale Garbee