Bug 31619

Summary: sudo new security issue CVE-2023-27320
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Sysadmin Team <sysadmin-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal    
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: sudo-1.9.12p2-1.mga9.src.rpm CVE:
Status comment:

Description David Walser 2023-03-02 23:30:24 CET
Sudo has issued an advisory on February 27:
https://www.sudo.ws/security/advisories/double_free/

The issue is fixed upstream in 1.9.13p2:
https://www.sudo.ws/releases/stable/#1.9.13p2

Mageia 8 is not affected.

Ubuntu has issued an advisory for this today (March 2):
https://ubuntu.com/security/notices/USN-5908-1

Freeze move request has been submitted yesterday but it hasn't been moved yet.
Comment 1 David Walser 2023-03-03 16:58:07 CET
sudo-1.9.13p2-1.mga9.src.rpm moved to core/release.

Status: NEW => RESOLVED
Resolution: (none) => FIXED