From f0df0be3cdadd729c77b6a504296c18079c73112985ebb56a6b5dd7e7b802033 Mon Sep 17 00:00:00 2001 From: Jason Sikes Date: Sun, 22 Jan 2023 22:07:43 +0000 Subject: [PATCH] Accepting request 1060306 from home:jsikes:branches:Base:System Fix that addresses bsc#1207082. Enjoy! OBS-URL: https://build.opensuse.org/request/show/1060306 OBS-URL: https://build.opensuse.org/package/show/Base:System/sudo?expand=0&rev=227 --- sudo-1.9.12p1.tar.gz | 3 --- sudo-1.9.12p1.tar.gz.sig | Bin 566 -> 0 bytes sudo-1.9.12p2.tar.gz | 3 +++ sudo-1.9.12p2.tar.gz.sig | Bin 0 -> 566 bytes sudo.changes | 24 ++++++++++++++++++++++++ sudo.spec | 4 ++-- 6 files changed, 29 insertions(+), 5 deletions(-) delete mode 100644 sudo-1.9.12p1.tar.gz delete mode 100644 sudo-1.9.12p1.tar.gz.sig create mode 100644 sudo-1.9.12p2.tar.gz create mode 100644 sudo-1.9.12p2.tar.gz.sig diff --git a/sudo-1.9.12p1.tar.gz b/sudo-1.9.12p1.tar.gz deleted file mode 100644 index 299f61a..0000000 --- a/sudo-1.9.12p1.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:475a18a8eb3da8b2917ceab063a6baf51ea09128c3c47e3e0e33ab7497bab7d8 -size 4908060 diff --git a/sudo-1.9.12p1.tar.gz.sig b/sudo-1.9.12p1.tar.gz.sig deleted file mode 100644 index 034ebaa26cb7c8d934cbbeb7104a8dc75e03f0ab8c0a4caad739c0361eeb3b83..0000000000000000000000000000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 566 zcmV-60?GY}0y6{v0SEvc79j*#(do>(D>r8Z{nJ~i^uQs`q;UHM0%K)%+5id(5UKRQ zA>{NM&~7kHVcE>eI7~hJ{kWhS(<*$LlZQYOBLKFO=%M{ec-6 zntp`!8v5AoYw187CG#PjNwUT&HOZ)9E_M{6+*=#>weDG=X;Mv`JoJfYvO zHpEdBQtMW2JEJ^ev_J-v42o8$ zX#%g&7Uiz|e2`c{aO3`;ok0tDS6)qu{~-Z;KB~4FCOM3Jo87>Su&_pLx9S;zGx0iX zl~+yUCJ=?ET!hLnjvmXp&Wkmd;3Z2Y%`}#j#jn%Aw5%m3NXubkd4G* zOTfTJBqX7d&qVH=3!^efi_`iXU(A98PWh>$Q!VQc2mtvUO;1VDj8KondvSI`GX(qP z%K>gx;5AqloPTIP6j(E(?GeNq8Y!XB6g~qlf@GjUqn5?n2qEov?cEy#VHTDuW9_uh zu9u^+YPa@@uM9TDe|RZp8~f_I_dVwpz9ORYU3ZxRzQxI5Z|h&k+hvQrUPg(kZ5O;p zUYKlgFQnAQ1Gd7z6=m*$@!E&(xmvFPU659bB``vh^N1C|zyU(NZ53~{D4GnUz zfQ~RZDf293Zrn72n~=J@43U~xMVv{_`}y??uOGO(c537dKn|igBpyg`9j0<|Z@QO9 E#9D$9qW}N^ diff --git a/sudo-1.9.12p2.tar.gz b/sudo-1.9.12p2.tar.gz new file mode 100644 index 0000000..d526c05 --- /dev/null +++ b/sudo-1.9.12p2.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:b9a0b1ae0f1ddd9be7f3eafe70be05ee81f572f6f536632c44cd4101bb2a8539 +size 4909431 diff --git a/sudo-1.9.12p2.tar.gz.sig b/sudo-1.9.12p2.tar.gz.sig new file mode 100644 index 0000000000000000000000000000000000000000000000000000000000000000..1d0ff2e4e4a8efceae3d377ba5b502e16dea44ffdc3a9c8b8d77647d3b5b32a2 GIT binary patch literal 566 zcmV-60?GY}0y6{v0SEvc79j*#(do>(D>r8Z{nJ~i^uQs`q;UHM0%OPkM*s>55UKRQ zA3thwr!3>Sv;Xmiu zNm|5ap{l%7{*Dt?!?Be(u;OMzCA<%6k6Qlh)O@|d-b(vu1{p=p%&}Epb~v$zw8J1r zAZJ7}3@zI~`fh#x`sPr$e}A}b(ww>ow=R4V&aXj3XcQ^kO6w^G)HROzvETKc0Sd+} zS6KQkqz2A$ZQ9yZJsQR`%I(@F5Vb%w2sjP6zBaPmJpE9BXayU1FPRy1)kb;dsulvO zd1`1wxc>=qTXhy(on?GHQE&_vj-?E0e3<=_qO@2=*#*~-XJ7H_ zMcAF6riI@dPDJgnBln?@VKC1{mp|y4KJZ@=nm5aC9rM1KMhvqvLTkU6AO>q%n(J9j z;|b=efam6lS`FgR;I$s{au;E0Y`@lUDsboA`K16WW3Osq|=WpT@H%J3_} zvsgCL6mq+_Nr%B@s|0$pw!Pel)gVb>CBnHjtk$zk8Sy)DTL literal 0 HcmV?d00001 diff --git a/sudo.changes b/sudo.changes index b2b1f24..06109f2 100644 --- a/sudo.changes +++ b/sudo.changes @@ -1,3 +1,27 @@ +------------------------------------------------------------------- +Thu Jan 19 03:39:52 UTC 2023 - Jason Sikes + +- Update to 1.9.12p2: + * Fixes bsc#1207082 + * Changes in 1.9.12p2: + Fixed a compilation error on Linux/aarch64. GitHub issue #197. + + Fixed a potential crash introduced in the fix GitHub issue #134. + If a user’s sudoers entry did not have any RunAs user’s set, + running sudo -U otheruser -l would dereference a NULL pointer. + + Fixed a bug introduced in sudo 1.9.12 that could prevent sudo + from creating a I/O files when the iolog_file sudoers setting + contains six or more Xs. + + Fixed a compilation issue on AIX with the native compiler. + GitHub issue #231. + + Fixed CVE-2023-22809, a flaw in sudo’s -e option (aka sudoedit) + that could allow a malicious user with sudoedit privileges to + edit arbitrary files. For more information, see Sudoedit can + edit arbitrary files. + ------------------------------------------------------------------- Mon Nov 21 22:25:54 UTC 2022 - Jason Sikes diff --git a/sudo.spec b/sudo.spec index 4de3ab4..a5187dc 100644 --- a/sudo.spec +++ b/sudo.spec @@ -1,7 +1,7 @@ # # spec file for package sudo # -# Copyright (c) 2022 SUSE LLC +# Copyright (c) 2023 SUSE LLC # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -17,7 +17,7 @@ Name: sudo -Version: 1.9.12p1 +Version: 1.9.12p2 Release: 0 Summary: Execute some commands as root License: ISC