[ubuntu/xenial-security] sudo 1.8.16-0ubuntu1.8 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Mon Oct 14 14:59:26 UTC 2019


sudo (1.8.16-0ubuntu1.8) xenial-security; urgency=medium

  * SECURITY UPDATE: privilege escalation via UID -1
    - debian/patches/CVE-2019-14287.patch: treat an ID of -1 as invalid
      in lib/util/strtoid.c.
    - CVE-2019-14287
    - debian/patches/CVE-2019-14287-2.patch: fix and add to tests in
      lib/util/regress/atofoo/atofoo_test.c,
      plugins/sudoers/regress/testsudoers/test5.out.ok,
      plugins/sudoers/regress/testsudoers/test5.sh.
    - CVE-2019-14287

Date: 2019-10-11 11:58:18.068957+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/sudo/1.8.16-0ubuntu1.8
-------------- next part --------------
Sorry, changesfile not available.


More information about the Xenial-changes mailing list