[ubuntu/natty] sudo 1.7.4p4-5ubuntu3 (Accepted)

Jamie Strandboge jamie at ubuntu.com
Thu Jan 20 15:15:41 UTC 2011


sudo (1.7.4p4-5ubuntu3) natty; urgency=low

  * SECURITY UPDATE: privilege escalation via -g when using group Runas_List
    - debian/patches/CVE-2011-0010.patch: prompt for password when the user is
      running sudo as himself but as a different group
    - CVE-2011-0010

Date: Tue, 18 Jan 2011 16:37:09 -0600
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/natty/+source/sudo/1.7.4p4-5ubuntu3
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 18 Jan 2011 16:37:09 -0600
Source: sudo
Binary: sudo sudo-ldap
Architecture: source
Version: 1.7.4p4-5ubuntu3
Distribution: natty
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Description: 
 sudo       - Provide limited super user privileges to specific users
 sudo-ldap  - Provide limited super user privileges to specific users
Changes: 
 sudo (1.7.4p4-5ubuntu3) natty; urgency=low
 .
   * SECURITY UPDATE: privilege escalation via -g when using group Runas_List
     - debian/patches/CVE-2011-0010.patch: prompt for password when the user is
       running sudo as himself but as a different group
     - CVE-2011-0010
Checksums-Sha1: 
 9a7ea31212b6f6f35e71f9b97a836770f21551c6 1870 sudo_1.7.4p4-5ubuntu3.dsc
 8f956a58f154581a8ac447d85a271835b5ebfd0b 27488 sudo_1.7.4p4-5ubuntu3.debian.tar.gz
Checksums-Sha256: 
 d2fe8590c1c66991a7a60bc0d7b24496bf670ad3a96f983c1d328a50fc5d0e9b 1870 sudo_1.7.4p4-5ubuntu3.dsc
 d99c1e616d2afe9f5b639e750e5bab365f0e654565d326cad9c356d75e6646b3 27488 sudo_1.7.4p4-5ubuntu3.debian.tar.gz
Files: 
 ca0a06980bbf8df468b897c672225b60 1870 admin optional sudo_1.7.4p4-5ubuntu3.dsc
 4167e45b02c0f14fd79e9549aebcde1a 27488 admin optional sudo_1.7.4p4-5ubuntu3.debian.tar.gz
Original-Maintainer: Bdale Garbee <bdale at gag.com>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQIcBAEBCgAGBQJNNyRYAAoJEFHb3FjMVZVzSycP/i9pf+uQdK4707jz1lpRSuIg
TqeTBsud6QU+FX9EeS0dDSuT/8deBa/OptZYXd8nlux5Bn84c5XcgsDX4kbKpK9j
Gfctb7Zb0J+sszsvnClqCeeo/6Eg/l/9eg3ZTlsUk6MaDlErKJcXWC5H+HzT/nDW
Fb6I+s2sMdsd5ORrALDviDMH34fLE+E+Rh6ha9fzNytBZFCQ0zdgKzPMigBtp+D7
Qi7M0Y0a62uEs37dxUJzUMR5o7YL11wKNvN+vHKOodH5XfU7AadE5u/x8OXIBQt3
NVdNK8RABvFBREVLUTY5PihF5xFBnzlR8JDMKkICNkGv/m1HqzQGQG7Yb695UOJM
5HS71OEAZd2d1PFbF1qWdEteVVGJlkyKQ/yLUCYV49ub65k2bH2OPGQNIpGWvfCz
3sIentCGpIFrIctUNbKwZw/4kvQ4Y3IS8ySb2sb3FIaYhXQkOxGroO1FXDOeJuYz
J74NyqIGrEnLPv1sz8lMivE40iNizBkFO346MyLQaWjHk19eujn87zAQitHcArAh
ESa32WGMMGAT1kBs4ww2812nJL5PbbHA8GppIzIZHTGyC19OxZY77DxGHXBeH6eg
MuHAbA2ym+SS2bJeboTVhowh/QE6BzqGl25nAC6KD6HCKxCV5P+9sugog1bfrTnD
pjYwytqOdRtt5rBH5AVp
=DNog
-----END PGP SIGNATURE-----


More information about the Natty-changes mailing list