From: Marcin Juszkiewicz Date: Tue, 22 Nov 2005 15:00:10 +0000 (+0000) Subject: sudo: upgrade to 1.6.8p12 due to CVE-2005-1993 X-Git-Tag: Release-2010-05/1~9453^2~3030^2~4^2~3 X-Git-Url: http://git.openpandora.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=521f9e0029d97055d7cd8cade39924b76718ff41;p=openembedded.git sudo: upgrade to 1.6.8p12 due to CVE-2005-1993 - Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack. - Thanks to Jamie Lenehan for notice - close #486 --- diff --git a/packages/sudo/sudo_1.6.8p8.bb b/packages/sudo/sudo_1.6.8p12.bb similarity index 95% rename from packages/sudo/sudo_1.6.8p8.bb rename to packages/sudo/sudo_1.6.8p12.bb index cc8ae4081c..f9d55411f8 100644 --- a/packages/sudo/sudo_1.6.8p8.bb +++ b/packages/sudo/sudo_1.6.8p12.bb @@ -5,4 +5,3 @@ SRC_URI = "http://ftp.sudo.ws/sudo/dist/sudo-${PV}.tar.gz \ file://noexec-link.patch;patch=1" include sudo.inc -PR = "r4"