[ubuntu/jammy-security] sudo 1.9.9-1ubuntu2.3 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Thu Mar 2 13:53:59 UTC 2023


sudo (1.9.9-1ubuntu2.3) jammy-security; urgency=medium

  * SECURITY UPDATE: double free with per-command chroot sudoers rules
    - debian/patches/CVE-2023-27320.patch: don't free user_cmnd twice in
      MANIFEST, plugins/sudoers/match_command.c,
      plugins/sudoers/regress/fuzz/fuzz_sudoers.c,
      plugins/sudoers/regress/testsudoers/test20.out.ok,
      plugins/sudoers/regress/testsudoers/test20.sh,
      plugins/sudoers/testsudoers.c,
      plugins/sudoers/visudo.c.
    - CVE-2023-27320

Date: 2023-03-01 14:50:10.358697+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/sudo/1.9.9-1ubuntu2.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list