pkgsrc/security/sudo
spz 00d2dec648 update to version 1.8.20p2
upstream changelog:
2017-05-31  Todd C. Miller  <Todd.Miller@courtesan.com>

        * NEWS, configure, configure.ac:
        Sudo 1.8.20p2
        [47836f4c9834]

        * src/ttyname.c:
        A command name may also contain newline characters so read
        /proc/self/stat until EOF. It is not legal for /proc/self/stat to
        contain embedded NUL bytes so treat the file as corrupt if we see
        any. With help from Qualys.

        This is not exploitable due to the /dev traversal changes in sudo
        1.8.20p1 (thanks Solar!).
        [15a46f4007dd]

2017-05-30  Todd C. Miller  <Todd.Miller@courtesan.com>

        * src/ttyname.c:
        Use /proc/self consistently on Linux. As far as I know, only AIX
        doesn't support /proc/self.
        [6f3d9816541b]
2017-06-07 05:41:53 +00:00
..
patches sudo: include the full regen of configure script. 2017-05-31 02:33:12 +00:00
DESCR
distinfo update to version 1.8.20p2 2017-06-07 05:41:53 +00:00
Makefile update to version 1.8.20p2 2017-06-07 05:41:53 +00:00
MESSAGE Stop mentioning sudo version prior 1.6 - it was over 16 years ago. 2016-10-21 20:50:42 +00:00
options.mk Use OPSYSVARS. 2016-02-26 09:41:05 +00:00
PLIST Add nls as an option, but also fix builds where system gettext gets detected and used. 2016-01-09 11:22:12 +00:00