Bug 25568 - sudo new security issue CVE-2019-14287
Summary: sudo new security issue CVE-2019-14287
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-10-14 21:31 CEST by David Walser
Modified: 2019-10-17 00:24 CEST (History)
4 users (show)

See Also:
Source RPM: sudo-1.8.27-1.mga7.src.rpm
CVE: CVE-2019-14287
Status comment:


Attachments

Description David Walser 2019-10-14 21:31:17 CEST
Sudo has issued an advisory today (October 14):
https://www.sudo.ws/alerts/minus_1_uid.html

The issue is fixed upstream in 1.8.28:
https://www.sudo.ws/stable.html#1.8.28

Mageia 7 is also affected.
David Walser 2019-10-14 21:31:26 CEST

Whiteboard: (none) => MGA7TOO

Comment 1 Lewis Smith 2019-10-15 09:15:37 CEST
'sudo' has no registered maintainer, so assigning this globally.

Assignee: bugsquad => pkg-bugs

Comment 2 Nicolas Salguero 2019-10-15 10:28:45 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Potential bypass of Runas user restrictions. (CVE-2019-14287)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14287
https://www.sudo.ws/alerts/minus_1_uid.html
https://www.sudo.ws/stable.html#1.8.28
========================

Updated packages in core/updates_testing:
========================
sudo-1.8.28-1.mga7
sudo-devel-1.8.28-1.mga7

from SRPMS:
sudo-1.8.28-1.mga7.src.rpm

Assignee: pkg-bugs => qa-bugs
Version: Cauldron => 7
CC: (none) => nicolas.salguero
Whiteboard: MGA7TOO => (none)
CVE: (none) => CVE-2019-14287
Status: NEW => ASSIGNED

Comment 3 Morgan Leijström 2019-10-15 17:00:06 CEST
Just testing it works on mga7 64bit:  OK

[morgan@svarten ~]$ LC_ALL=C sudo --version
Sudo version 1.8.28
Sudoers policy plugin version 1.8.28
Sudoers file grammar version 46
Sudoers I/O plugin version 1.8.28

[morgan@svarten ~]$ sudo whoami
[sudo] lösenord för morgan: 
root

CC: (none) => fri

Thomas Backlund 2019-10-16 23:48:21 CEST

CC: (none) => tmb, sysadmin-bugs
Keywords: (none) => advisory, validated_update
Whiteboard: (none) => MGA7-64-OK

Comment 4 Mageia Robot 2019-10-17 00:24:06 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2019-0298.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.