sudo 1.9.15b1 released
"Todd C. Miller via sudo-workers" <[email protected]> Thu, 19 Oct 2023 10:50:50 -0600
| Newsgroups | gmane.comp.tools.sudo.devel |
|---|---|
| Message-ID | <[email protected]> |
--===============4984940511812717609==
Content-Type: multipart/signed; protocol="application/pgp-signature";
micalg=pgp-; boundary="44821_Thu_Oct_19_10_50_35_MDT_2023"
--44821_Thu_Oct_19_10_50_35_MDT_2023
Content-Type: text/plain; charset=us-ascii
The first beta release of sudo 1.9.15 is now available. In addition
to bug fixes, sudo 1.9.15 includes changes to make it easier to
determine which sudoers rule permitted a command to be run.
Source:
https://www.sudo.ws/dist/beta/sudo-1.9.15b1.tar.gz
ftp://ftp.sudo.ws/pub/sudo/beta/sudo-1.9.15b1.tar.gz
SHA256 checksum:
4f08def04e47fb601fed9cf4884e5c84e0bb3d0ec0e85dd7a6098bc91f43725f
MD5 checksum:
546819964bd2e72325ac926f406d5b73
Binary packages:
https://www.sudo.ws/getting/beta_packages/
For a list of download mirror sites, see:
https://www.sudo.ws/getting/download_mirrors/
Sudo web site:
https://www.sudo.ws/
Major changes between sudo 1.9.15b1 and 1.9.14p3:
* Fixed an undefined symbol problem on older versions of macOS
when "intercept" or "log_subcmds" are enabled in sudoers.
GitHub issue #276.
* Fixed "make check" failure related to getpwent(3) wrapping
on NetBSD.
* Fixed the warning message for "sudo -l command" when the command
is not permitted. There was a missing space between "list" and
the actual command due to changes in sudo 1.9.14.
* Fixed a bug where output could go to the wrong terminal if
"use_pty" is enabled (the default) and the standard input, output
or error is redirected to a different terminal. Bug #1056.
* The visudo utility will no longer create an empty file when the
specified sudoers file does not exist and the user exits the
editor without making any changes. GitHub issue #294.
* The AIX and Solaris sudo packages on www.sudo.ws now support
"log_subcmds" and "intercept" with both 32-bit and 64-bit
binaries. Previously, they only worked when running binaries
with the same word size as the sudo binary. GitHub issue #289.
* The sudoers source is now logged in the JSON event log. This
makes it possible to tell which rule resulted in a match.
* Running "sudo -ll command" now produces verbose output that
includes matching rule as well as the path to the sudoers file
the matching rule came from. For LDAP sudoers, the name of the
matching sudoRole is printed instead.
* The embedded copy of zlib has been updated to version 1.3.
* The sudoers plugin has been modified to make it more resilient
to ROWHAMMER attacks on authentication and policy matching.
This addresses CVE-2023-42465.
* The sudoers plugin now constructs the user time stamp file path
name using the user-ID instead of the user name. This avoids a
potential problem with user names that contain a path separator
('/') being interpreted as part of the path name. A similar
issue in sudo-rs has been assigned CVE-2023-42456.
* A path separator ('/') in a user, group or host name is now
replaced with an underbar character ('_') when expanding escapes
in @include and @includedir directives as well as the "iolog_file"
and "iolog_dir" sudoers Default settings.
* The "intercept_verify" sudoers option is now only applied when
the "intercept" option is set in sudoers. Previously, it was
also applied when "log_subcmds" was enabled. Sudo 1.9.14
contained an incorrect fix for this. Bug #1058.
* Changes to terminal settings are now performed atomically, where
possible. If the command is being run in a pseudo-terminal and
the user's terminal is already in raw mode, sudo will not change
the user's terminal settings. This prevents concurrent sudo
processes from restoring the terminal settings to the wrong values.
GitHub issue #312.
--44821_Thu_Oct_19_10_50_35_MDT_2023
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEWdHpzLorN2cE/dNbqfTAIc6kcPsFAmUxXlsACgkQqfTAIc6k
cPu0URAAqrIZj3bujP8cBvbHaq0j4/XILzwpMIbEZeq/FlOCvnwHJ91qG+1p2pNe
owcevk2KahNxO9E+nvSgQ0cx4ZZeuxhMP5YfoDkmaoe0EUE+K67qqAiGMJMh4mvZ
AoOy9j2+9vWYNtahz3GQrhrSeeCzgTRtBrC1fppk4FV3iyu/zPJF6TqNtKJ8x8g8
ma9MvgVseMh5csLMrAWbqpOJcFMKMfzkS3f346rl144igKGQk2hxArBk1vEqdx/5
uopWyPoG3YZB4Gt7kldrzErxjLM8emlr56Nxe3I5QHXwzfv3+gLrvzII1TJ4FloN
tLv7DoR7X5Dyg5Z5UnzqX6oZYWFZsyIZTtY0fenJDs34RZdPjGLO16Ff9vvSzeLc
dGrLZFBqri1qwHR2ZIuj7Di+n4Cw4A3HTJWjsfy7RPcPcN7RVYJy2VW7X8LpA9tW
OlfMM7+zja39VcK/0Ex2EbZJfD7sEJN3czfwaK6kvoq3prCzPnKt9nZlmCM2IlNA
bMHknMH0fspNRS0bLkdv1WZFljp33dt1IzBlk0N0yttqgwWH4qUuo/0lh/3ZOpZW
zJTg8vau8iClxQM4jDs44H5p/5rYti6q0BgzXTK0UJsuJXojGJLsv+BPhhmd9ANn
mNrhb9E5xFVzhUROV2wJLKAdJ2nGXhOjI3LAGMXSf0iXNwHhjA4=
=g7lG
-----END PGP SIGNATURE-----
--44821_Thu_Oct_19_10_50_35_MDT_2023--
--===============4984940511812717609==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
____________________________________________________________
sudo-workers mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-workers
--===============4984940511812717609==--