Files
buildroot/package
Christian Stewart 05983bbbe8 package/sudo: security bump to version 1.9.5p2
Major changes between sudo 1.9.5p2 and 1.9.5p1

 * Buildroot: dropped a patch that was included in the release.

 * Fixed sudo's setprogname(3) emulation on systems that don't
   provide it.

 * Fixed a problem with the sudoers log server client where a partial
   write to the server could result the sudo process consuming large
   amounts of CPU time due to a cycle in the buffer queue. Bug #954.

 * Added a missing dependency on libsudo_util in libsudo_eventlog.
   Fixes a link error when building sudo statically.

 * The user's KRB5CCNAME environment variable is now preserved when
   performing PAM authentication.  This fixes GSSAPI authentication
   when the user has a non-default ccache.

 * When invoked as sudoedit, the same set of command line options
   are now accepted as for "sudo -e".  The -H and -P options are
   now rejected for sudoedit and "sudo -e" which matches the sudo
   1.7 behavior.  This is part of the fix for CVE-2021-3156.

 * Fixed a potential buffer overflow when unescaping backslashes
   in the command's arguments.  Normally, sudo escapes special
   characters when running a command via a shell (sudo -s or sudo
   -i).  However, it was also possible to run sudoedit with the -s
   or -i flags in which case no escaping had actually been done,
   making a buffer overflow possible.  This fixes CVE-2021-3156.

https://www.sudo.ws/stable.html#1.9.5p2

Signed-off-by: Christian Stewart <christian@paral.in>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 4fea71ac78)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2021-01-28 21:09:15 +01:00
..
2020-09-14 22:16:23 +02:00
2020-09-30 22:56:40 +02:00
2020-10-06 21:05:07 +02:00
2020-11-29 22:15:42 +01:00
2020-11-18 10:48:11 +01:00
2020-09-02 18:14:46 +02:00
2020-09-22 21:41:06 +02:00
2020-10-13 13:23:33 +02:00
2020-11-09 11:00:11 +01:00
2020-09-01 09:18:37 +02:00
2020-11-26 17:10:02 +01:00
2020-10-04 11:38:01 +02:00
2020-09-09 22:54:26 +02:00
2020-10-31 22:22:28 +01:00
2020-11-12 21:53:32 +01:00
2020-11-09 17:01:30 +01:00
2020-11-04 20:34:48 +01:00
2020-11-01 10:03:36 +01:00
2020-09-17 21:40:39 +02:00
2020-11-01 10:03:36 +01:00
2020-10-12 08:33:42 +02:00
2020-08-29 23:05:20 +02:00
2020-09-21 22:37:31 +02:00
2020-08-29 21:58:02 +02:00
2020-11-03 23:16:48 +01:00
2020-10-15 23:36:40 +02:00
2020-09-20 16:08:09 +02:00
2020-09-07 23:15:11 +02:00
2020-09-08 22:31:51 +02:00
2020-11-07 13:21:15 +01:00
2020-11-29 22:21:37 +01:00
2020-08-29 22:57:17 +02:00
2020-12-01 23:01:27 +01:00
2020-11-10 08:29:37 +01:00
2020-10-25 15:52:40 +01:00
2020-09-19 21:10:27 +02:00
2020-10-31 23:44:06 +01:00
2020-10-04 20:45:35 +02:00
2020-12-13 00:54:16 +01:00
2020-08-28 22:56:49 +02:00
2020-10-31 23:01:00 +01:00
2020-11-07 14:19:01 +01:00
2020-09-19 21:18:26 +02:00
2020-09-05 23:30:10 +02:00
2020-10-18 13:28:37 +02:00
2020-11-22 15:26:49 +01:00
2021-01-28 20:24:04 +01:00
2020-09-20 15:36:47 +02:00
2020-10-04 21:53:43 +02:00
2020-10-24 22:58:03 +02:00
2020-08-26 23:23:44 +02:00
2020-08-29 23:13:51 +02:00
2020-09-19 14:52:33 +02:00
2020-08-27 23:04:17 +02:00
2020-09-03 20:51:04 +02:00
2020-11-16 21:29:58 +01:00
2020-09-19 14:22:00 +02:00
2020-08-28 22:56:49 +02:00
2020-09-19 22:08:37 +02:00
2020-10-31 21:42:38 +01:00
2020-11-03 20:55:04 +01:00
2020-10-27 10:25:41 +01:00
2020-10-06 21:04:37 +02:00
2020-08-31 22:18:09 +02:00
2020-10-15 00:09:48 +02:00
2020-09-22 21:59:02 +02:00
2020-10-13 13:33:33 +02:00
2020-10-04 11:38:01 +02:00
2020-11-22 15:31:36 +01:00
2021-01-28 18:23:43 +01:00
2021-01-05 22:52:08 +01:00
2020-10-12 22:30:09 +02:00
2020-08-28 22:56:49 +02:00
2020-10-04 11:38:01 +02:00
2020-09-20 15:05:59 +02:00
2021-01-28 18:00:46 +01:00
2020-10-29 23:26:21 +01:00
2021-01-28 20:24:04 +01:00
2020-11-12 21:55:11 +01:00
2020-12-12 12:02:27 +01:00
2020-09-19 23:22:59 +02:00
2021-01-12 18:25:27 +01:00
2020-09-20 15:06:00 +02:00
2020-11-01 10:03:36 +01:00
2021-01-28 20:24:04 +01:00
2021-01-19 15:55:42 +01:00