Format: 1.8 Date: Tue, 19 Jan 2021 09:21:02 -0500 Source: sudo Binary: sudo sudo-ldap Architecture: s390x s390x_translations Version: 1.8.31-1ubuntu1.2 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: sudo - Provide limited super user privileges to specific users sudo-ldap - Provide limited super user privileges to specific users Changes: sudo (1.8.31-1ubuntu1.2) focal-security; urgency=medium . * SECURITY UPDATE: dir existence issue via sudoedit race - debian/patches/CVE-2021-23239.patch: fix potential directory existing info leak in sudoedit in src/sudo_edit.c. - CVE-2021-23239 * SECURITY UPDATE: heap-based buffer overflow - debian/patches/CVE-2021-3156-pre1.patch: sanity check size when converting the first record to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-1.patch: reset valid_flags to MODE_NONINTERACTIVE for sudoedit in src/parse_args.c. - debian/patches/CVE-2021-3156-2.patch: add sudoedit flag checks in plugin in plugins/sudoers/policy.c. - debian/patches/CVE-2021-3156-3.patch: fix potential buffer overflow when unescaping backslashes in plugins/sudoers/sudoers.c. - debian/patches/CVE-2021-3156-4.patch: fix the memset offset when converting a v1 timestamp to TS_LOCKEXCL in plugins/sudoers/timestamp.c. - debian/patches/CVE-2021-3156-5.patch: don't assume that argv is allocated as a single flat buffer in src/parse_args.c. - CVE-2021-3156 Checksums-Sha1: 019ff579c55ea4f8b548d41e1a67a782ea49a6e4 1271584 sudo-dbgsym_1.8.31-1ubuntu1.2_s390x.ddeb ffee7db7403b256ec333727346cc120078f9388f 1320412 sudo-ldap-dbgsym_1.8.31-1ubuntu1.2_s390x.ddeb 55d5096266c0f3f03962c4bd85de51fc9414f7b5 501636 sudo-ldap_1.8.31-1ubuntu1.2_s390x.deb 307cef4fa44423b84460e33b92ad808008687ae8 7397 sudo_1.8.31-1ubuntu1.2_s390x.buildinfo 5871d4ffe37f3763b0a58f3a258ef06804cd8eb9 466704 sudo_1.8.31-1ubuntu1.2_s390x.deb ab0d5cd7c36d22d0f4c341b9fca7df1cf8a604cf 2066009 sudo_1.8.31-1ubuntu1.2_s390x_translations.tar.gz Checksums-Sha256: 84dc6d2b5c818d37b6243b9041165c28313c67a0636494bac4bbcfd89ef0b013 1271584 sudo-dbgsym_1.8.31-1ubuntu1.2_s390x.ddeb 500c332f7f9b0c01c1e65026c63fa3223257c76bddd72bff4491f1900b564cc9 1320412 sudo-ldap-dbgsym_1.8.31-1ubuntu1.2_s390x.ddeb a05ac296990167600484c45cc7fe26ea933585dfbe5d20494757f52798d42919 501636 sudo-ldap_1.8.31-1ubuntu1.2_s390x.deb b6dfa763c527cf3140f5eefd4bf5890f9b76cd61c7e4afac2efd212e1c3156f0 7397 sudo_1.8.31-1ubuntu1.2_s390x.buildinfo 00d2ce0611a30af5b262e2eaa0a49067c76a4d48b7b5ab391413257c46146b95 466704 sudo_1.8.31-1ubuntu1.2_s390x.deb 6b33643774bcf1a9c7b99f3e9e772cfd2e32684911d1426a253a1edd1183d6de 2066009 sudo_1.8.31-1ubuntu1.2_s390x_translations.tar.gz Files: 12bbf5ebbe397b37f6706cf6f7853797 1271584 debug optional sudo-dbgsym_1.8.31-1ubuntu1.2_s390x.ddeb 03aa312c6edf57f1f0b5eb162366a857 1320412 debug optional sudo-ldap-dbgsym_1.8.31-1ubuntu1.2_s390x.ddeb aab2b859b1000ff58b74da1b7e008b16 501636 admin optional sudo-ldap_1.8.31-1ubuntu1.2_s390x.deb 5897d8275f5d01ab9b907d0562a8187f 7397 admin optional sudo_1.8.31-1ubuntu1.2_s390x.buildinfo e48f6913205ea360be2dc1c7fc5183cd 466704 admin optional sudo_1.8.31-1ubuntu1.2_s390x.deb 0e950583d462473b9f8183c63a513082 2066009 raw-translations - sudo_1.8.31-1ubuntu1.2_s390x_translations.tar.gz Original-Maintainer: Bdale Garbee