==========================================================================
Ubuntu Security Notice USN-4263-1
February 03, 2020
sudo vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 19.10
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS
Summary:
Sudo could allow unintended access to the administrator account.
Software Description:
– sudo: Provide limited super user privileges to specific users
Details:
Joe Vennix discovered that Sudo incorrectly handled memory operations when
the pwfeedback option is enabled. A local attacker could possibly use this
issue to obtain unintended access to the administrator account.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 19.10:
sudo 1.8.27-1ubuntu4.1
sudo-ldap 1.8.27-1ubuntu4.1
Ubuntu 18.04 LTS:
sudo 1.8.21p2-3ubuntu1.2
sudo-ldap 1.8.21p2-3ubuntu1.2
Ubuntu 16.04 LTS:
sudo 1.8.16-0ubuntu1.9
sudo-ldap 1.8.16-0ubuntu1.9
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/4263-1
CVE-2019-18634
Package Information:
https://launchpad.net/ubuntu/+source/sudo/1.8.27-1ubuntu4.1
https://launchpad.net/ubuntu/+source/sudo/1.8.21p2-3ubuntu1.2
https://launchpad.net/ubuntu/+source/sudo/1.8.16-0ubuntu1.9
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl44LecACgkQZWnYVadE
vpO6jQ/+OQFdJYYHF45P1TvnmHH8QHQu2ycJssJQSGja8sN3Umn7KJzWQ5FKRnA0
W1mnNywLFocjlTOlcmvHOXy87QdU2Tyiai1k7oYarY6cNqpfOWsF+g39JlXu12Tl
0fM0+HUZn0tB3xrIBQc+XZ5R3188WlrfcH20OrCX9hQ5uf6HOzC2XSI14ZPtg4ZV
1dGzMmwSRarj4JSTafQGEMeE1iPBsiAss9hc6yM+qmO2NUI+6P7+NJKlcKGndHAN
dnyp+kJ15NfeVGjtIU24HiWwiVw0Kkg1LYfJQeGPuhW62iOW7AI5oWJHPB4DBCBy
rY5nfObKHO7MSz+NIgs2jFLJRw38OlqquDA6IYhPd39uuDC8hhr008dFXprEwBsP
ivtLbcm6EeAoP+zJ1sf+BMHnn72mCoiGp52lfS5NrYJOuE0RP14ncfo8BQwaoHG7
io+Hr5Z1CWc0ystF9SkJy+J4Jd2O3Kjp6PJd9Dk7l+IrMzUxorLjzfrkZA8LNrp/
XMJsRud+h5poO1IA7zfo5hr5uxgsmGZx0ZBC1EH8cF0p1GMiKDfSdvc1LF8tuS9b
4AFpIJrGWMNC8NT3xOxc/bDrEi+/tahVt7Tcm1sWrT2xjTxsQ1F7ceu67hwCR+eP
pZB9JO6DrjhCH14FnSrXWV7pMb1GS3fNai2opvl4f4QUXlth4dk=
=RUCp
—–END PGP SIGNATURE—–
—