Bug#1032163: sudo: CVE-2023-27320

2023-03-07 Thread Leandro Cunha
Control: tags -1 fixed-upstream X-Debbugs-Cc: s...@packages.debian.org It has already been resolved by upstream. Sudo before 1.9.13p2 has a double free in the per-command chroot feature. This issue does not affect bullseye (see https://security-tracker.debian.org/tracker/CVE-2023-27320). Just

Bug#1032163: sudo: CVE-2023-27320

2023-02-28 Thread Salvatore Bonaccorso
Source: sudo Version: 1.9.13p1-1 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for sudo, filling as RC aiming to have it fixed before bookworm release. CVE-2023-27320[0]: | Sudo before 1.9.13p2 has a