Summary: | security/sudo: Update to 1.9.12p1 | ||||||
---|---|---|---|---|---|---|---|
Product: | Ports & Packages | Reporter: | Cy Schubert <cy> | ||||
Component: | Individual Port(s) | Assignee: | Cy Schubert <cy> | ||||
Status: | Closed FIXED | ||||||
Severity: | Affects Many People | CC: | garga, grahamperrin, ports-bugs, ports-secteam | ||||
Priority: | Normal | Keywords: | needs-patch, security | ||||
Version: | Latest | Flags: | garga:
maintainer-feedback+
koobs: merge-quarterly? |
||||
Hardware: | Any | ||||||
OS: | Any | ||||||
URL: | https://www.sudo.ws/releases/stable/#1.9.12p1 | ||||||
Attachments: |
|
Description
Cy Schubert
2022-11-07 14:22:51 UTC
Approved. Thank you! A commit in branch main references this bug: URL: https://cgit.FreeBSD.org/ports/commit/?id=271b349b390a6036d501ed3d27c0189ff3d43e47 commit 271b349b390a6036d501ed3d27c0189ff3d43e47 Author: Cy Schubert <cy@FreeBSD.org> AuthorDate: 2022-11-07 14:18:09 +0000 Commit: Cy Schubert <cy@FreeBSD.org> CommitDate: 2022-11-07 15:33:45 +0000 security/sudo: Update to 1.9.12p1 This release includes fixes to minor bugs, including a fix for CVE-2022-43995, a non-exploitable potential out-of-bounds write on systems that do not use PAM, AIX authentication or BSD authentication. PR: 267617 Approved by: garga (Maintainer) MFH: 2022Q4 Security: CVE-2022-43995 security/sudo/Makefile | 2 +- security/sudo/distinfo | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) ^Triage: - [tags] in Summary are deprecated - Re-open pending MFH - Doesn't look like VuXML entry has been added yet - Assign to committer resolving A commit in branch 2022Q4 references this bug: URL: https://cgit.FreeBSD.org/ports/commit/?id=4d74603950cae23c69d9e07c27effa093b9b58a5 commit 4d74603950cae23c69d9e07c27effa093b9b58a5 Author: Cy Schubert <cy@FreeBSD.org> AuthorDate: 2022-11-07 14:18:09 +0000 Commit: Cy Schubert <cy@FreeBSD.org> CommitDate: 2022-11-08 00:04:06 +0000 security/sudo: Update to 1.9.12p1 This release includes fixes to minor bugs, including a fix for CVE-2022-43995, a non-exploitable potential out-of-bounds write on systems that do not use PAM, AIX authentication or BSD authentication. PR: 267617 Approved by: garga (Maintainer) Security: CVE-2022-43995 (cherry picked from commit 271b349b390a6036d501ed3d27c0189ff3d43e47) security/sudo/Makefile | 2 +- security/sudo/distinfo | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) A commit in branch main references this bug: URL: https://cgit.FreeBSD.org/ports/commit/?id=3cd785707f9dc7b53396ecfd729d1fba07c3ca04 commit 3cd785707f9dc7b53396ecfd729d1fba07c3ca04 Author: Cy Schubert <cy@FreeBSD.org> AuthorDate: 2022-11-08 00:16:07 +0000 Commit: Cy Schubert <cy@FreeBSD.org> CommitDate: 2022-11-08 00:18:23 +0000 security/vuxml: Document sudo CVE-2022-43995 Document a potential out-of-bounds write for passwords smaller than eight bytes when crypt() is used. PR: 267617 Security: CVE-2022-43995 security/vuxml/vuln-2022.xml | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) Committed and merged to quarterly. Added vuxml. |