[ubuntu/lucid-security] sudo, sudo (delayed) 1.7.2p1-1ubuntu5.2 (Accepted)

Ubuntu Installer archive at ubuntu.com
Tue Sep 7 14:04:00 BST 2010


sudo (1.7.2p1-1ubuntu5.2) lucid-security; urgency=low

  * SECURITY UPDATE: privilege escalation via '-g' option when using
    'user:group' in Runas_Spec
    - update match.c to verify both user and group match sudoers when using
      '-g'. Patch thanks to upstream.
    - CVE-2010-2956

Date: Tue, 31 Aug 2010 15:16:00 -0500
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/lucid/+source/sudo/1.7.2p1-1ubuntu5.2
-------------- next part --------------
Format: 1.8
Date: Tue, 31 Aug 2010 15:16:00 -0500
Source: sudo
Binary: sudo sudo-ldap
Architecture: source
Version: 1.7.2p1-1ubuntu5.2
Distribution: lucid-security
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Description: 
 sudo       - Provide limited super user privileges to specific users
 sudo-ldap  - Provide limited super user privileges to specific users
Changes: 
 sudo (1.7.2p1-1ubuntu5.2) lucid-security; urgency=low
 .
   * SECURITY UPDATE: privilege escalation via '-g' option when using
     'user:group' in Runas_Spec
     - update match.c to verify both user and group match sudoers when using
       '-g'. Patch thanks to upstream.
     - CVE-2010-2956
Checksums-Sha1: 
 5fb76eb561e42aaed175212c5ba53b98f867bb6d 1131 sudo_1.7.2p1-1ubuntu5.2.dsc
 ca96e03aa99e787b07c84bda6927808eb5a89c33 26583 sudo_1.7.2p1-1ubuntu5.2.diff.gz
Checksums-Sha256: 
 22b2f40369900c54879d9eda9cc51a358beb8374ba832995fd1d82f24c7ecd48 1131 sudo_1.7.2p1-1ubuntu5.2.dsc
 52808c86489925d512e31c6c5b515ef360258b0d86d6b1e10e49bdbd211a0362 26583 sudo_1.7.2p1-1ubuntu5.2.diff.gz
Files: 
 456ecc22f3b88cb3e60dbfac679b110a 1131 admin optional sudo_1.7.2p1-1ubuntu5.2.dsc
 f3077ddbefcc852cb66d71ec63e0013c 26583 admin optional sudo_1.7.2p1-1ubuntu5.2.diff.gz
Original-Maintainer: Bdale Garbee <bdale at gag.com>


More information about the Lucid-changes mailing list