Opened 7 years ago

Closed 7 years ago

#9293 closed enhancement (fixed)

sudo-1.8.20p1

Reported by: bdubbs@… Owned by: bdubbs@…
Priority: high Milestone: 8.1
Component: BOOK Version: SVN
Severity: normal Keywords:
Cc:

Description

New patch version.

Change History (4)

comment:1 by bdubbs@…, 7 years ago

Owner: changed from blfs-book@… to bdubbs@…
Status: newassigned

comment:2 by Douglas R. Reno, 7 years ago

Priority: normalhigh

This is a fix for a critical security vulnerability according to the US Department of Homeland Security.

comment:3 by bdubbs@…, 7 years ago

What's new in Sudo 1.8.20p1

  • Fixed "make check" when using OpenSSL or GNU crypt. Bug #787.
  • Fixed CVE-2017-1000367, a bug parsing /proc/pid/stat on Linux when the process name contains spaces. Since the user has control over the command name, this could potentially be used by a user with sudo access to overwrite an arbitrary file on systems with SELinux enabled. Also stop performing a breadth-first traversal of /dev when looking for the device; only a hard-coded list of directories are checked,

comment:4 by bdubbs@…, 7 years ago

Resolution: fixed
Status: assignedclosed

Fixed at revision 18799.

Note: See TracTickets for help on using tickets.