From 7b07d36c9c463eb0692ff58146f01d3dffe8c454 Mon Sep 17 00:00:00 2001 From: Kevin Daudt <kdaudt@alpinelinux.org> Date: Tue, 26 Jan 2021 18:41:19 +0000 Subject: [PATCH] main/sudo: security upgrade to 1.9.5p2 (CVE-2021-3156) See: #12356 --- main/sudo/APKBUILD | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/main/sudo/APKBUILD b/main/sudo/APKBUILD index 17f88a00ce0e..76254db7f3b9 100644 --- a/main/sudo/APKBUILD +++ b/main/sudo/APKBUILD @@ -2,7 +2,7 @@ # Contributor: Åukasz Jendrysik <scadu@yandex.com> # Maintainer: Natanael Copa <ncopa@alpinelinux.org> pkgname=sudo -pkgver=1.9.5p1 +pkgver=1.9.5p2 if [ "${pkgver%_*}" != "$pkgver" ]; then _realver=${pkgver%_*}${pkgver#*_} else @@ -23,6 +23,8 @@ options="suid" builddir="$srcdir/sudo-$_realver" # secfixes: +# 1.9.5p2-r0: +# - CVE-2021-3156 # 1.9.5-r0: # - CVE-2021-23239 # - CVE-2021-23240 @@ -67,6 +69,6 @@ package() { rm -rf "$pkgdir"/var/run } -sha512sums="0168f0b61a6c2d2f60a92b5b4d3c3254aed4116decabac3821d9ac2fd7f74bb7b019e35bb8955335315b3b00ddf4e4acd82540df0addc1d9bf4f44b60447a878 sudo-1.9.5p1.tar.gz +sha512sums="f0fe914963c31a6f8ab6c86847ff6cdd125bd5a839b27f46dcae03963f4fc413b3d4cca54c1979feb825c8479b44c7df0642c07345c941eecf6f9f1e03ea0e27 sudo-1.9.5p2.tar.gz f476bb5ac02c3222d3be7eecb828131374e0baf806cc0fd548fb9d4a90f40a848d0ef58851a63ea1d988b720fe259312f3a457ca994ac0e93ed9e16fc72d5234 fix-cross-compile.patch 03a2cef9fcc26cc2711edb5928c945fcf214b22139bb88d77538d25f3bfd144d17b6c9dabb1e01960ac1697d83b3452397a5ef4c7d0e68ea72548a631b212e6d SIGUNUSED.patch" -- GitLab