[ubuntu/disco-security] sudo 1.8.27-1ubuntu1.1 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Mon Oct 14 14:59:28 UTC 2019


sudo (1.8.27-1ubuntu1.1) disco-security; urgency=medium

  * SECURITY UPDATE: privilege escalation via UID -1
    - debian/patches/CVE-2019-14287.patch: treat an ID of -1 as invalid
      in lib/util/strtoid.c.
    - debian/patches/CVE-2019-14287-2.patch: fix and add to tests in
      lib/util/regress/atofoo/atofoo_test.c,
      plugins/sudoers/regress/testsudoers/test5.out.ok,
      plugins/sudoers/regress/testsudoers/test5.sh.
    - CVE-2019-14287

Date: 2019-10-11 11:56:14.005259+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/sudo/1.8.27-1ubuntu1.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Disco-changes mailing list