[ubuntu/xenial-security] sudo 1.8.16-0ubuntu1.8 (Accepted)
Leonidas S. Barbosa
leo.barbosa at canonical.com
Mon Oct 14 14:59:26 UTC 2019
sudo (1.8.16-0ubuntu1.8) xenial-security; urgency=medium
* SECURITY UPDATE: privilege escalation via UID -1
- debian/patches/CVE-2019-14287.patch: treat an ID of -1 as invalid
in lib/util/strtoid.c.
- CVE-2019-14287
- debian/patches/CVE-2019-14287-2.patch: fix and add to tests in
lib/util/regress/atofoo/atofoo_test.c,
plugins/sudoers/regress/testsudoers/test5.out.ok,
plugins/sudoers/regress/testsudoers/test5.sh.
- CVE-2019-14287
Date: 2019-10-11 11:58:18.068957+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/sudo/1.8.16-0ubuntu1.8
-------------- next part --------------
Sorry, changesfile not available.
More information about the Xenial-changes
mailing list