openwrt-packages/admin/sudo
Josef Schlehofer bee91a9d88 sudo: backport patches for CVE-2021-3156
This security vulnerability is known as Baron Samedit [1] and there is a
research by Qualys [2] and they discovered it. Unfortunately or
fortunately, there isn't present sudoedit on OpenWrt.

Two patches were applied cleanly and the other two required manual
intervention. Those were backported from version 1.9.5p2

[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3156
[2] https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit

Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com>
2021-01-28 10:09:00 -10:00
..
files sudo: imported from oldpackages repo, updated to version 1.8.11p2 2014-12-16 08:39:13 +01:00
patches sudo: backport patches for CVE-2021-3156 2021-01-28 10:09:00 -10:00
Makefile sudo: backport patches for CVE-2021-3156 2021-01-28 10:09:00 -10:00