-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 29 Jun 2017 15:50:30 -0400 Source: sudo Binary: sudo sudo-ldap Architecture: source amd64 Version: 1.8.5p2-1+nmu3+deb7u4 Distribution: wheezy-security Urgency: high Maintainer: Bdale Garbee <bdale@gag.com> Changed-By: Antoine Beaupré <anarcat@debian.org> Description: sudo - Provide limited super user privileges to specific users sudo-ldap - Provide limited super user privileges to specific users Changes: sudo (1.8.5p2-1+nmu3+deb7u4) wheezy-security; urgency=high . * Non-maintainer upload by the LTS Security Team. * CVE-2017-1000368: Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution. Checksums-Sha1: e849fc9cc831628863664a7c8a369bef94b07df0 1970 sudo_1.8.5p2-1+nmu3+deb7u4.dsc 68111c3e58545d4b7837a6b3afcb0122edca2470 129516 sudo_1.8.5p2-1+nmu3+deb7u4.debian.tar.gz 7ea8fce89dee6d97dd543aaf1b6deb5fe69c3a1c 853694 sudo_1.8.5p2-1+nmu3+deb7u4_amd64.deb 2f2ad00eb5b8028158eddb989831d374a33be4f8 874008 sudo-ldap_1.8.5p2-1+nmu3+deb7u4_amd64.deb Checksums-Sha256: 84c17426d8c8d4c84d141e2f2b49540a4b3f103548bb305e7b2fbd9e08b9b40c 1970 sudo_1.8.5p2-1+nmu3+deb7u4.dsc 25b069583918b7001fb0cbe651de4d211b0d5bf2dca66864bf0cba1481c200be 129516 sudo_1.8.5p2-1+nmu3+deb7u4.debian.tar.gz e5ff3f4d29674c1f329e0d575ff08fc9de6d86e3e3318142afa76b16598d14f7 853694 sudo_1.8.5p2-1+nmu3+deb7u4_amd64.deb 924d64c15b877f709789baf8447ba7bb7466e24fc444fcc23e54e6429f290472 874008 sudo-ldap_1.8.5p2-1+nmu3+deb7u4_amd64.deb Files: beeab2f6552a2ea0c53a232ac09ab4cd 1970 admin optional sudo_1.8.5p2-1+nmu3+deb7u4.dsc 6e30bd6e89f04a0d1c9a905274c176bf 129516 admin optional sudo_1.8.5p2-1+nmu3+deb7u4.debian.tar.gz 979ca9cddf97f1faeb21463201d80200 853694 admin optional sudo_1.8.5p2-1+nmu3+deb7u4_amd64.deb 9494989f5b63cb6d9c431e943250dcf0 874008 admin optional sudo-ldap_1.8.5p2-1+nmu3+deb7u4_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEjckBzmQUbASK1Q+7eSFSUnt1kh4FAllaVYgACgkQeSFSUnt1 kh77xw//YZ8p3+LRbYVY9BmJNeL9KghPDv6p77TjaYsUhOvt42xIdLPMd3NCLrwj H/Q+u28VZS8T6nkOwpr5lp1fVlKX5aesJJqyIFvaZuA8rRl6fQa215og0ML0ba30 kpGTB3axQB1HAnZMUxjE4CUxQMb/DVhx9XdmZZJ6IOyjBYcBbs2QTppytKN0F+Gt hGii62/Q4z+x01AtldbWtOLixPrIIdHGu08w9CTEinvXc9uMLfBoiVOvFepiIbJ3 S5wgYwSYNJX2ARIIQlsAyLUgNQp+zhnMsL+/6EapxTwtDTzazCzvG+SlBSouLXVi yHE3AMepU0qqzxYfdWxMto0IJ3oK3w53PkhxIMwnxOK7OU/3GTg5qy50T6exSWIR kzj6Qf3lfgpJkbPYFfocjo40lv879ZVq/LAdxJRsMOQTdZbc2mkZxcDXw2LwMD1J GdJJ6XFmj43iRZVi5XSRJp2qyptGWyDm3CoN3bCy7MQnCeS1jp0ON4kgH+JfZX2m FM4AkeBKEKtSd1SNMfDsm6R8AuHHopqKS7zQOaMekYsxwlyeDEk4ATk37y5TSAAV VE7Oq1vpyNqLFYQ97FEy5Sui0Tgbe6JLjP4zzis2UIX9OjMc2UjSpzQY3Kwj1+00 YsH94DlLalq5KPUfH0gwm9DaIetDDhUNx1H6I/ONu6Tqq8HlFh0= =0s3v -----END PGP SIGNATURE-----