Debian Security Advisory

DLA-1011-1 sudo -- LTS security update

Date Reported:
03 Jul 2017
Affected Packages:
sudo
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 863897.
In Mitre's CVE dictionary: CVE-2017-1000368.
More information:

Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.

The previous announcement (DLA-970-1) was about a similar security issue (CVE-2017-1000367) which wasn't completely fixed.

For Debian 7 Wheezy, these problems have been fixed in version 1.8.5p2-1+nmu3+deb7u4.

We recommend that you upgrade your sudo packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS