sudo 1.9.8 released
"Todd C. Miller" <[email protected]> Mon, 13 Sep 2021 09:22:33 -0600
| Newsgroups | gmane.comp.tools.sudo.announce |
|---|---|
| Message-ID | <[email protected]> |
--===============6715839607377833363==
Content-Type: multipart/signed; protocol="application/pgp-signature";
micalg=pgp-; boundary="29549_Mon_Sep_13_09_22_26_MDT_2021"
--29549_Mon_Sep_13_09_22_26_MDT_2021
Content-Type: text/plain; charset=us-ascii
Sudo version 1.9.8 now available. In addition to bug fixes, sudo
1.9.8 adds a new "intercept" mode that can be used to intercept the
exec family of library functions in the command run by sudo and do
a policy check on sub-commands before they are executed. Intercept
mode uses LD_PRELOAD to communicate with the main sudo process to
perform the sudoers check. As such, there are some limitations.
See the sudoers man page for details.
Sudo 1.9.8 also includes a new sudoers setting, log_subcmds, which
works like intercept mode but only logs the command that was run
and does not validate it against the sudoers file.
Source:
https://www.sudo.ws/dist/sudo-1.9.8.tar.gz
ftp://ftp.sudo.ws/pub/sudo/sudo-1.9.8.tar.gz
SHA256 checksum:
f1735de999804ea1af068fba6a82cb6674ea64c789813b29266fd3b16cb294e6
MD5 checksum:
0a38acd342112b86e8163a26818bdbbd
Binary packages:
https://www.sudo.ws/download.html#binary
https://github.com/sudo-project/sudo/releases/tag/SUDO_1_9_8
For a list of download mirror sites, see:
https://www.sudo.ws/download_mirrors.html
Sudo web site:
https://www.sudo.ws/
Sudo web site mirrors:
https://www.sudo.ws/mirrors.html
Major changes between sudo 1.9.8 and 1.9.7p2:
* It is now possible to transparently intercepting sub-commands
executed by the original command run via sudo. Intercept support
is implemented using LD_PRELOAD (or the equivalent supported by
the system) and so has some limitations. The two main limitations
are that only dynamic executables are supported and only the
execl, execle, execlp, execv, execve, execvp, and execvpe library
functions are currently intercepted. Its main use case is to
support restricting privileged shells run via sudo.
To support this, there is a new "intercept" Defaults setting and
an INTERCEPT command tag that can be used in sudoers. For example:
Cmnd_Alias SHELLS=/bin/bash, /bin/sh, /bin/csh, /bin/ksh, /bin/zsh
Defaults!SHELLS intercept
would cause sudo to run the listed shells in intercept mode.
This can also be set on a per-rule basis. For example:
Cmnd_Alias SHELLS=/bin/bash, /bin/sh, /bin/csh, /bin/ksh, /bin/zsh
chuck ALL = INTERCEPT: SHELLS
would only apply intercept mode to user "chuck" when running one
of the listed shells.
In intercept mode, sudo will not prompt for a password before
running a sub-command and will not allow a set-user-ID or
set-group-ID program to be run by default. The new
intercept_authenticate and intercept_allow_setid sudoers settings
can be used to change this behavior.
* The new "log_subcmds" sudoers setting can be used to log additional
commands run in a privileged shell. It uses the same mechanism as
the intercept support described above and has the same limitations.
* Support for logging sudo_logsrvd errors via syslog or to a file.
Previously, most sudo_logsrvd errors were only visible in the
debug log.
* Better diagnostics when there is a TLS certificate validation error.
* Using the "+=" or "-=" operators in a Defaults setting that takes
a string, not a list, now produces a warning from sudo and a
syntax error from inside visudo.
* Fixed a bug where the "iolog_mode" setting in sudoers and sudo_logsrvd
had no effect when creating I/O log parent directories if the I/O log
file name ended with the string "XXXXXX".
* Fixed a bug in the sudoers custom prompt code where the size
parameter that was passed to the strlcpy() function was incorrect.
No overflow was possible since the correct amount of memory was
already pre-allocated.
* The mksigname and mksiglist helper programs are now built with
the host compiler, not the target compiler, when cross-compiling.
Bug #989.
* Fixed compilation error when the --enable-static-sudoers configure
option was specified. This was due to a typo introduced in sudo
1.9.7. GitHub PR #113.
--29549_Mon_Sep_13_09_22_26_MDT_2021
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEWdHpzLorN2cE/dNbqfTAIc6kcPsFAmE/bLIACgkQqfTAIc6k
cPvfOhAAxBsK0ckbUxxyFPPJFopf9dnXfNuRc1jZyYwEqAChwJNPctd+qSrubKu/
AIhZgrd2si0KEgpurIJVgusSA2MtkaIqpGC3ZS2yMB4taXbUBgF3KjVs5Gxukx7G
kcqOPwE6m+L5Lcvv8yDMwDWV76zelumSncJPJ41lk+5OECZ8yp9Fl7pdFEMlxHIP
INtRnmCdbxKEYt+UrVD9rv/VgThSLCETyo6qYiRUKLGTnafQp/zODR5ofy2lbv++
Gkx0r/+++Ki85P9TgfqgqNxQpExSSYtUllvBRWTKyfrfhjN1rwo9zGAU8udh3xh8
9N/+KNNBDTWfJWPsJiQaZqIXfuMBv5sQdwjx+ISPlj2qnN9L7AD6KNamTq1RfyUa
FrrCCQVG0oE8dpbN7KitCTpv2tnRNRfPS8mv5IbN262BlLE0JLI4cSZmYu9aZSmf
C7ug0S+zyQQEQ4+zFOd5cYZRgduYz3LNBIshyrOZcGFyvuVNaZlEBfy9dE69mw/e
36V6YIX9lFS0D7lMxiXgSgaHBNIG0dh0dUxn3LeIrerNKfDkdvise0qyGycDRU8G
tMTm4Q4qxcvWsXzjCqEVZBNXwEhNFvSJw+n5TkwXIHKcB7ke4LCS8a7lRqXhccd7
KmNCJnP0RTjdEalLz8g5h3oaYU6OfInJYrOqUeu6gV9y9/kghSE=
=UajP
-----END PGP SIGNATURE-----
--29549_Mon_Sep_13_09_22_26_MDT_2021--
--===============6715839607377833363==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
____________________________________________________________
sudo-announce mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-announce
--===============6715839607377833363==--