Package: sudo
Version: 1.9.13p3-1
Severity: important
Tags: patch upstream

Dear Maintainer,

The sudo event log format is broken when environment variables are set.
the " ; " (space, semicolon, space) that separates the environment
variables from the following logged object (usually the actual command
itself) has been lost.

This has been reported as issue #254 upstream:
https://github.com/sudo-project/sudo/issues/254

The issue has been fixed with this patch:
https://github.com/sudo-project/sudo/commit/12648b4e0a8cf486480442efd52f0e0b6cab6e8b.patch

The issue impacts log parsing and filtering (e.g. with logcheck).

Kind regards,
+ Kimmo

-- System Information:
Debian Release: 12.0
  APT prefers stable-security
  APT policy: (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 6.1.0-9-amd64 (SMP w/2 CPU threads; PREEMPT)
Locale: LANG=C.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages sudo depends on:
ii  init-system-helpers  1.65.2
ii  libaudit1            1:3.0.9-1
ii  libc6                2.36-9
ii  libpam-modules       1.5.2-6
ii  libpam0g             1.5.2-6
ii  libselinux1          3.4-1+b6
ii  zlib1g               1:1.2.13.dfsg-1

sudo recommends no packages.

sudo suggests no packages.

-- Configuration Files:
/etc/sudoers [Errno 13] Permission denied: '/etc/sudoers'
/etc/sudoers.d/README [Errno 13] Permission denied: '/etc/sudoers.d/README'

-- no debconf information

Reply via email to