FFe: Update to sudo 1.8.16
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
sudo (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
I am requesting a FeatureFreeze exception to update sudo in Xenial to the newly released 1.8.16 version.
Not only does the new 1.8.16 version fix a large number of bugs, but it also fixes security issues:
- CVE-2015-5602: privilege escalation via symlink attack
- CVE-2015-8239: race condition checking digests/checksums in sudoers
- duplicate environment variable handling
The fixes for these issues are intrusive and difficult to backport.
Once 1.8.16 is in Xenial, I intend to backport it to Precise and Trusty as a security update to fix the long standing issue with sudo and timestamp files based on the local clock which resulting in a big refactoring of how timestamp files work in 1.8.10. (See bug 1219337)
See the following for details of the changes between 1.8.12 and 1.8.16:
https:/
I will of course monitor bugs and will fix any issues that arise.
Just to be clear, I will start by merging 1.8.15-1.1 from debian, and will update to 1.8.16 which isn't in Debian yet.