• [SECURITY] [DSA 3167-1] sudo security update

    From Salvatore Bonaccorso@1:229/2 to All on Sun Feb 22 11:20:01 2015
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3167-1 [email protected] http://www.debian.org/security/ Salvatore Bonaccorso February 22, 2015 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : sudo
    CVE ID : CVE-2014-9680
    Debian Bug : 772707

    Jakub Wilk reported that sudo, a program designed to provide limited
    super user privileges to specific users, preserves the TZ variable from
    a user's environment without any sanitization. A user with sudo access
    may take advantage of this to exploit bugs in the C library functions
    which parse the TZ environment variable or to open files that the user
    would not otherwise be able to open. The later could potentially cause
    changes in system behavior when reading certain device special files or
    cause the program run via sudo to block.

    For the stable distribution (wheezy), this problem has been fixed in
    version 1.8.5p2-1+nmu2.

    We recommend that you upgrade your sudo packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQIcBAEBCgAGBQJU6aw2AAoJEAVMuPMTQ89Elh0P/3TRIvCCeRT6ujltDmOnavnZ mL43sNp69KnIPxMzqk+6AzYhvKg2p1RMzA+cngu8vPTKT9LPZz0j2gRnz2PnRIyo nteQ7PlNyA/9Riz2tRVWVnvCMdTcf3TtJ0p16sUmOJLH5zXK5GRHC25Q9fK/JMjb PRv4W0IVUqXI/N8xm8uyfNdeQ98BFn1DTX1kJllqkdgrOHImeGQA61rGcAj5Nbwr 4tWrslnQmqi27A7Zz3GcmWzqc6mTzWJ1JLLsEaysKQXAkXOm8J3zyZKpUb+Sy2AG s5fDLRdXAWogkzAiJc3ilbIVvZGwIiRvHHkgDAx5eMrCftfNvTWsI45GaDyiq22P mrVj44MZjOWi2gVMkpeDXj/kgnOu8WL6w4BrTb8StW2HaAFV3wq7bjZgPTjJ/Ea+ AZxUq5W41jtNJ2vkOf/Slvox8IufHHs4QayPVczRGR0B9i/nwlAL6CoLyq2bqMtQ SmzNPGXA84DIVIQbYG0Q0S5bmxvvf/dVuH4DGKG+6wrW2Dts3S7yxJCUyNWA3r/I e9M+4G2qvEZVdDHEz3bRJR/dKfmtl12w8uAAYTYPRlaaYuX6j1Pg8Oyss2O7XX3a +og5Xygo5q7bbC1Jy6hvwWCXd4bMsY6Celk8+4Pm9sekBCO7tT0puFqKarml5Nf1 gG4LwpQhbHUXnH9gDS8d
    =em5a
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: https://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)