-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 15 Feb 2015 16:54:59 +0100 Source: sudo Binary: sudo sudo-ldap Architecture: source amd64 Version: 1.8.5p2-1+nmu2 Distribution: wheezy-security Urgency: high Maintainer: Bdale Garbee <bdale@gag.com> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: sudo - Provide limited super user privileges to specific users sudo-ldap - Provide limited super user privileges to specific users Closes: 772707 Changes: sudo (1.8.5p2-1+nmu2) wheezy-security; urgency=high . * Non-maintainer upload by the Security Team. * Add CVE-2014-9680-1.patch patch. CVE-2014-9680: unsafe handling of TZ environment variable. (Closes: #772707) * Add CVE-2014-9680-2.patch patch. Documents that a leading ':' is skipped when checking TZ for a fully-qualified path name. Checksums-Sha1: 98202fdf66aa49f79bf15ee30ee55f2df1a5e012 1878 sudo_1.8.5p2-1+nmu2.dsc 1bf378ffb6fef801a7f5d0ca90f8ab849f79d1be 1746344 sudo_1.8.5p2.orig.tar.gz dc868e03f18446a321bea876b110156601faa800 29554 sudo_1.8.5p2-1+nmu2.debian.tar.gz d1edb8c804b1647a6e8ab86644821b513a868ab8 848376 sudo_1.8.5p2-1+nmu2_amd64.deb eafe8788f86157177497b35a5742745d32c3f0c0 869022 sudo-ldap_1.8.5p2-1+nmu2_amd64.deb Checksums-Sha256: 6762978cb538fb3c5624a7e93d0d14f46743f76512c2ae2173ce5556629157b6 1878 sudo_1.8.5p2-1+nmu2.dsc c32ae2bc3faf83444c82ca75ccb10ad3684d8222e3535f164c4a4db7cdddf8cf 1746344 sudo_1.8.5p2.orig.tar.gz 0e81f1fe9d1d776d2a101b6fad7df1c55f63bb46049376e91fc44611a9f5d523 29554 sudo_1.8.5p2-1+nmu2.debian.tar.gz f8e0104bee5ff934e87169f3badd54f603d15ad858cc4c7e6db55a9777242318 848376 sudo_1.8.5p2-1+nmu2_amd64.deb bf6ed064d059189585ed9c2180b9419b48c64703c1bf3b8830a3777cbcb97223 869022 sudo-ldap_1.8.5p2-1+nmu2_amd64.deb Files: e953c92d9f8e44781454a131764d9ca2 1878 admin optional sudo_1.8.5p2-1+nmu2.dsc dc42ed9f0946d92273762d0ae7314d59 1746344 admin optional sudo_1.8.5p2.orig.tar.gz 5022b1ada96148e9c0fca9ac190408fc 29554 admin optional sudo_1.8.5p2-1+nmu2.debian.tar.gz 59f9eb6e3d3f331f5a0871a48fbbf6a3 848376 admin optional sudo_1.8.5p2-1+nmu2_amd64.deb 8e9c516594e1c4b115c2273436c2845a 869022 admin optional sudo-ldap_1.8.5p2-1+nmu2_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJU4fPuAAoJEAVMuPMTQ89EhmkP/1rsGJgqPUAnMMWZWu/+CsJl NIRzNf1qup0JqF0Tc3wxGuZ4rAmsSWRPalxUv4DbDtEMV72jjJzOawjP5Z7wxvSb XTSc4g2ownOVodePf0IdskNfumRsv2kmFRGrfNZf8yl05awNAG7dZ2/5vNvur54V x++TzgJHWL2MQSnm4SijQSJPVWwB1OPAtyBPGgR/8kSynoLmpFviVYUN0zlesvqB 37n/wFDSl2XB1cmLTGn5kMEGb83Z46fCJ2oUyV7du9BxenH8vMSMjs1nPzh1FT5g F0f1ALUgJiBi+BkJI7S76HJhQhKyKoRhdDxbfN+8UrEvq21/3ulVWUNjxM9DPbOO QqFRKEk00Nx/nZSr2I2aO4vU0HjGRvpLXvMR1qn1xg/QBx4+zW5+KGyEMSkJvAkw UZK/xgHXegg3kNoQX0joCZtp2ZMHCqPCthCW+RcSh4+V/dHxM1Hfo98dBq3QjNgK eSU5N/xDasJC5HsRn1Qj1wbvt8cI4l/EpH/tNZs8cFDubkb6GTVyRqo8V4sbUW0K whZyiPN5oaOwF4fQX/gtYssaw/wmhNn3y+fJfbwbRQFenfZxpZcaQAclTlUuVfvy QQuur55n9QtezZj6pMItX3GNQ2+C5czf0qN4fTGrNH20xbDAPxxh/hZG6HT0gOG7 Hh8ZIhmBGvdjQiFJK3Ez =/2do -----END PGP SIGNATURE-----