[DSA 5954-1] sudo security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5954-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
June 30, 2025                         https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : sudo
CVE ID         : CVE-2025-32462

Rich Mirch discovered that sudo, a program designed to provide limited
super user privileges to specific users, does not correctly handle the
host (-h or --host) option. Due to a bug the host option was not
restricted to listing privileges only and could be used when running a
command via sudo or editing a file with sudoedit. Depending on the rules
present in the sudoers file the flaw might allow a local privilege
escalation attack.

For the stable distribution (bookworm), this problem has been fixed in
version 1.9.13p3-1+deb12u2.

We recommend that you upgrade your sudo packages.

For the detailed security status of sudo please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/sudo

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmhinHpfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0S5fA/9H6Zq1F/AMF55WLyisdD3D2BF7guvoUMaEJdWe6OyaEoi8Dc2WT2br32t
zj6FpbBlMdKYGe5jPQAIWD8De/9hc+XLAen8q9Xee940amaZcM8r/6lAGdhQjGo2
cU/11ka14/e5RPtmM3stpS4wY39AHJ0soL2cLIjkPFFkMy1AuRYjgTui1eIaokKC
S5IH1wXC/+dv/OqStFR2LluF1LczFjsc4y0Dl6PgSMVRStvg9NAq3G8V444heuQa
NdlbFr84x7rCP4QOKrzd0h2WjJZV3dXXE392DOks54YCsdfk0MS0di2HEdVZscrE
RI9rWIyTxVX8hCxZRFEkYPRNl2Rm7hJ/YKFN7+lJTtl44IEk2DpBWDBO8xN+QymR
wLdkUz70QTKpO92sIEKiKog0DBcIIHF0xwuqvouLWhx53VYwtl0RyZBDsN9nSfJ0
J1ZRAzU8x8kKWFDmXBP6dQEtSGvyN3vIo15yFeE0TcNDiUuaREne/EPsluYFTyWn
JzhrtvICfzoK7Jn9L+N958M2LUgMIYFxZLpetUB+KfqfJ+x1NAXayfiZfm8BVMXU
Bvw2SfE9D8xrxfjg3g6HhY7JoJfOs50FPtvrTkky13AG7BfBWFl6vYrriov38Fgq
JkSNzh5GAoSHFCeksOXeztkuAQ8+t3BQah84XF8214jKCFqc/Gc=
=uyBl
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.