]> code.ossystems Code Review - openembedded-core.git/commit
sudo: backport patch to address CVE 2012-0809
authorJoshua Lock <josh@linux.intel.com>
Thu, 1 Mar 2012 00:34:27 +0000 (16:34 -0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Thu, 1 Mar 2012 15:58:50 +0000 (15:58 +0000)
commit286cdd5db60b4f668e75cd9e05efb97acb08b7a6
tree8bb181df383ea77e9f0789ca12a13e15df247750
parent6461543ad955c3afa3f9d194373d0c8314d6dd7f
sudo: backport patch to address CVE 2012-0809

This is a format string vulnerability "that can be used to crash
sudo or potentially allow an unauthorized user to elevate privileges."

Signed-off-by: Joshua Lock <josh@linux.intel.com>
meta/recipes-extended/sudo/files/format-string.patch [new file with mode: 0644]
meta/recipes-extended/sudo/sudo_1.8.1p2.bb