Debian Patches

Status for sudo/1.9.5p2-3+deb11u1

Patch Description Author Forwarded Bugs Origin Last update
typo-in-classic-insults.diff no
paths-in-samples.diff no
Whitelist-DPKG_COLORS-environment-variable.diff [PATCH] Whitelist DPKG_COLORS environment variable Guillem Jover <guillem@hadrons.org> no 2016-05-04
fix-no-root-mailer.diff # HG changeset patch
# User Todd C. Miller <Todd.Miller@sudo.ws>
# Date 1611924154 25200
# Node ID e0d4f196ba027604154f79ddd03a0b90f90c9607
# Parent cd1c7615e861083e9e9b61d0e0070354e227ea5c
Fix NO_ROOT_MAILER, broken by the eventlog refactor in sudo 1.9.4.
init_eventlog_config() is called immediately after initializing the
Defaults settings, which is before struct sudo_user is setup. This
adds a call to eventlog_set_mailuid() if NO_ROOT_MAILER is defined
after the invoking user is determined. Reported by Roman Fiedler.
no
sudo-ldap-docs Adapt README.LDAP to the actual state of the sudo-ldap package Marc Haber <mh+debian-packages@zugschlus.de> no
CVE-2023-22809.patch sudoedit: do not permit editor arguments to include "--"
We use "--" to separate the editor and arguments from the files to edit.
If the editor arguments include "--", sudo can be tricked into allowing
the user to edit a file not permitted by the security policy.
Thanks to Matthieu Barjole and Victor Cutillas of Synacktiv
(https://synacktiv.com) for finding this bug.
no upstream

All known versions for source package 'sudo'

Links