[sudo-users] No more security fixes for sudo 1.8.x?
Todd C. Miller
Todd.Miller at sudo.ws
Tue Feb 9 16:03:54 MST 2021
On Thu, 04 Feb 2021 15:36:46 +0100, Colin Finck wrote:
> With CVE-2021-3156, CVE-2021-23239, and CVE-2021-23240, there have been
> three critical security issues lately, which are fixed in the latest
> sudo 1.9.5p2 release, but also affect sudo 1.8.31p2 as far as I know.
>
> Some Linux distros like Ubuntu that are on the 1.8.x branch have already
> backported the fix themselves, but others (like Yocto/OpenEmbedded)
> still seem to be waiting for an official fix for the 1.8 branch.
Sudo 1.8.32 has been released which includes fixes for CVE-2021-23239,
CVE-2021-23240 and CVE-2021-3156.
- todd
More information about the sudo-users
mailing list