sudo 1.9.17 released
"Todd C. Miller via sudo-announce" <[email protected]> Sat, 21 Jun 2025 10:21:32 -0600
| Newsgroups | gmane.comp.tools.sudo.announce |
|---|---|
| Message-ID | <[email protected]> |
--===============3229074529363320528==
Content-Type: multipart/signed; protocol="application/pgp-signature";
micalg=pgp-; boundary="88093_Sat_Jun_21_10_21_24_MDT_2025"
--88093_Sat_Jun_21_10_21_24_MDT_2025
Content-Type: text/plain; charset=us-ascii
Sudo version 1.9.17 is now available. This is primarily a bug fix
release.
Source:
https://www.sudo.ws/dist/sudo-1.9.17.tar.gz
ftp://ftp.sudo.ws/pub/sudo/sudo-1.9.17.tar.gz
SHA256 checksum:
3f212c69d534d5822b492d099abb02a593f91ca99f5afde5cb9bd3e1dcdad069
MD5 checksum:
c25b8d4fdd3837bcb83478866f50d4ff
Binary packages:
https://www.sudo.ws/getting/packages/
https://github.com/sudo-project/sudo/releases/tag/v1.9.17
For a list of download mirror sites, see:
https://www.sudo.ws/getting/download_mirrors/
Sudo web site:
https://www.sudo.ws/
Major changes between sudo 1.9.17 and 1.9.16p2:
* Sudo now uses the NODEV macro consistently. Bug #1074.
* Fixed a bug where the "ALL" command in a sudoers rule would
override a previous NOSETENV tag. Command tags are inherited
from previous Cmnds in a Cmnd_Spec_List. There is a special
case for the SETENV tag with the "ALL" command, where SETENV is
implied if no explicit SETENV or NOSETENV tag is specified. This
special case did not take into account that a NOSETENV tag that
was inherited should override this behavior.
* If sudo is run via ssh without a terminal and a password is
required, it now suggest using ssh's "-t" option.
* Fixed the display of timeout values in the "sudo -V" output
on systems without a C99-compliant snprintf() function.
* Quieted a number of minor Coverity warnings.
* Fixed a problem running sudo from a serial console on Linux when
the command is run in a pseudo-terminal (the default).
* Fixed a crash in sudo which could occur if there was a fatal
error after the user was validated but before the command was
actually run.
* Fixed a number of man page style warnings. The "lint" make target
in the docs directory will now run groff with warnings enabled
if it is available. Bug #1075.
* The "ignore_dot" sudoers setting is now on by default. There
is now a "--disable-ignore-dot" configure option to disable it.
The "--with-ignore-dot" configure option has been deprecated.
* Fixed a problem with the "pwfeedback" option where an initial
backspace would reduce the maximum length allowed for the password.
GitHub issue #439.
* Fixed minor grammar and spelling problems in the man pages.
* Fixed a bug where a user could avoid entering a password for
"sudo -l command" if they specified their own user or group name
via the "-u" or "-g" options.
* Avoid potential password guessing based on timing attacks on
the strcmp() function on systems without PAM or a crypt() function
where plaintext passwords are stored in the shadow password file.
* Fixed a potential information leak where "sudo -l command" could
be used to determine whether an executable exists in a directory
that they do not have search access to.
* Sudo uses TCSAFLUSH, not TCSADRAIN, when disabling echo once
again. A long time ago sudo changed from using TCSAFLUSH to
TCSADRAIN due to some systems having bugs related to TCSAFLUSH.
That should no longer be a concern. Using TCSAFLUSH ensures
that password input that has been received by the kernel, but
not yet read by sudo, will be discarded and not echoed.
* Added the SUDO_TTY environment variable if the user has a terminal.
This can be used to find the user's original tty device when sudo
runs the command in its own pseudo-terminal. GitHub issue #447.
* New Cantonese translation for sudo.
--88093_Sat_Jun_21_10_21_24_MDT_2025
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEWdHpzLorN2cE/dNbqfTAIc6kcPsFAmhW3AQACgkQqfTAIc6k
cPs2yQ//ShmOaSHu3g9df9O9zbeu71tALpDlyu+0rtkhtZ0GJzGekH00/EFL9xeK
JPmwKQby69giwg8+WaC7xIdDr3vEiESV89P09B2PIfbsPVbfSr2h1I3Cv5sqD3Bj
C90ZxrPJJQgue1pMXftvAP91OUaeRyGMLQ0qCYXxsxir9Hg1ZM9rNzk+wnP/npvB
5+RmNWY4R7FI+T1b9opWxVl+31dInlA/Uc9HjrwUoe4ClrhJYyjJ3dBBCr4JbSH/
poEDLWcKQ9PnCW1w+o2RMgcAuKWRv5VGzyxmzmv1kImG20+c0AgC7iRG3CERzDFt
S7Y+Fjo4LABcBUaHgIzoHQjdib4nA2fxSZmFNs3A4oggRTr2L9ed0VZKn3nidexx
T6oMlANss+RZO6CDPwIOeW75pofCgYN7yV8PJG4YjRwiCdtd0yoprPZNnzuUJ3+p
nRWj4LB64j1gDuToo4fB2dH0Yj4OZIjIcV8TF/vSj90YSSSiqXvRkIBRRjfI6jJq
Z0MxlulfccDKRurCGMA6lQLz5cbZuNpA3VygUwNoqWPmVlpoSWCdQr79WSQEL6ah
9PIv2SeexcAs06vXQcNW3ykU281xDogwn+JCHadPN2NF2QmzWV18HjLR3E04sMOA
d9oa4vTCdleQeJAqlbriLVoAPni23mILf4btiKsLyAff2MPPUzo=
=q/6Y
-----END PGP SIGNATURE-----
--88093_Sat_Jun_21_10_21_24_MDT_2025--
--===============3229074529363320528==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
____________________________________________________________
sudo-announce mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-announce
--===============3229074529363320528==--