From nobody Wed Jan 18 20:15:55 2023 X-Original-To: dev-commits-ports-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Nxxph3kqCz2stKp; Wed, 18 Jan 2023 20:15:56 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Nxxph36vNz3xPJ; Wed, 18 Jan 2023 20:15:56 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1674072956; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=t5rQpn/UcghK+sCQsnJ+8PSxOQHM9C+f2bFpd7THwZk=; b=r3F0Lb/Sp4DlG/rwZuqbie7wEIswHq2od5h3MQCiNsUsoEiOJhEJnbqhPywAEjuEdbiaBi m6Gs1YOEBLXYIkYXJw0GT8QApCR/stRyHviXQYP2p8dhVvnMweamOA4MjPMb1AdarGhq57 AP/Aiw3Dp5DDYLj1Ymb+xeA7OY3u0jGUZqg2LsKMg50WPy/euMAJKEtQPY1q0+wM89euHi Bzr2z8wQXWKnAlM1mkJTzAt2eo83S4NrcpM8SPZ2h0Inx4P3rek0ugKZUZi1rfG3LutoIK 9uHYQAwrhZO4+/ovabayP4gyCjgdiNlxHt2fO2d+CPuI9iKjYt9URB9Yxyucew== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1674072956; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=t5rQpn/UcghK+sCQsnJ+8PSxOQHM9C+f2bFpd7THwZk=; b=J3dXq7X1jkg9ZlGln25rGPmkku889aw35mZE1LBYxK9m+1ODgraIgqAHD0PRcPTW9azR7M iMRu9hOUss2r9YJLIJBOAd6cHMzxApGQHLa0Mp/a+RFgiHHBn1kMYWPdJnGzfIIgnC5OVi Mmx38tscBH4g7ByDtYgEe1PH5epUsL0/Kwf42MDv8+k75HTiTeB/hzlnEK732W1ZJFXKN0 up8E125c3HbaO6jlwp+iEtcPCQAVicLIUuZ7ihk4dKhEFOwc5wOWSJ8TjgNFLAwoadBJ2/ d8lLC8zj3/dSM7sjdRxkccHn6Dhzv5J0ghYOfId8xa4UShtLoJjeAe86SfNVXg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1674072956; a=rsa-sha256; cv=none; b=ENY8veUcTrFuD6FMhKOgG7f3c91ozeIp1OgKfHZvW2V6etL2mlNJbjzHv2KFVsyxLS3kv3 oseXFjKWrPfOTYbPqM1gez9ND2ayQGkXfbKg8Y+bHyiTXCIRg58s7sig+74y6PNCLhQ1tM +10kSY+VL6ReK1dbS228gJSjKoQ/TP4vsZaTC06MfebwJPGhtboL1p8dCT/ZzC0MyeQNsl tPULS2MgSje8dm90orTzvZxaKN2F0qziOYohK8sRRQjhTIj7nkqd6gdHM00w7ehmQBAUDF 7WQd6K4ZIBG3S4CrzguO82SBJOJp0L3e1ioYHXy3BtglG2LSlN7F3sihNyzrDg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Nxxph23x3zPTC; Wed, 18 Jan 2023 20:15:56 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 30IKFtPR068529; Wed, 18 Jan 2023 20:15:55 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 30IKFtUw068528; Wed, 18 Jan 2023 20:15:55 GMT (envelope-from git) Date: Wed, 18 Jan 2023 20:15:55 GMT Message-Id: <202301182015.30IKFtUw068528@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-branches@FreeBSD.org From: Renato Botelho Subject: git: e4b0eefa1832 - 2023Q1 - security/sudo: Update to 1.9.12p2 List-Id: Commits to the quarterly branches of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-branches@freebsd.org X-BeenThere: dev-commits-ports-branches@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: garga X-Git-Repository: ports X-Git-Refname: refs/heads/2023Q1 X-Git-Reftype: branch X-Git-Commit: e4b0eefa183226d3d6cb8be568a5a3aa586c12b9 Auto-Submitted: auto-generated X-ThisMailContainsUnwantedMimeParts: N The branch 2023Q1 has been updated by garga: URL: https://cgit.FreeBSD.org/ports/commit/?id=e4b0eefa183226d3d6cb8be568a5a3aa586c12b9 commit e4b0eefa183226d3d6cb8be568a5a3aa586c12b9 Author: Cy Schubert AuthorDate: 2023-01-18 16:20:58 +0000 Commit: Renato Botelho CommitDate: 2023-01-18 20:15:38 +0000 security/sudo: Update to 1.9.12p2 Major changes between sudo 1.9.12p2 and 1.9.12p1: * Fixed a compilation error on Linux/aarch64. GitHub issue #197. * Fixed a potential crash introduced in the fix for GitHub issue #134. If a user's sudoers entry did not have any RunAs user's set, running "sudo -U otheruser -l" would dereference a NULL pointer. * Fixed a bug introduced in sudo 1.9.12 that could prevent sudo from creating a I/O files when the "iolog_file" sudoers setting contains six or more Xs. * Fixed CVE-2023-22809, a flaw in sudo's -e option (aka sudoedit) that coud allow a malicious user with sudoedit privileges to edit arbitrary files. PR: 269030 Submitted by: cy Reported by: cy Approved by: garga MFH: 2023Q1 Security: CVE-2023-22809 (cherry picked from commit 8f8bd813f3139d6f6ff35704808111c4ad1f053a) --- security/sudo/Makefile | 2 +- security/sudo/distinfo | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/security/sudo/Makefile b/security/sudo/Makefile index 7318f194b669..673b94caf04f 100644 --- a/security/sudo/Makefile +++ b/security/sudo/Makefile @@ -1,5 +1,5 @@ PORTNAME= sudo -PORTVERSION= 1.9.12p1 +PORTVERSION= 1.9.12p2 CATEGORIES= security MASTER_SITES= SUDO diff --git a/security/sudo/distinfo b/security/sudo/distinfo index 909e14ed47f8..1820b31e549f 100644 --- a/security/sudo/distinfo +++ b/security/sudo/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1667830579 -SHA256 (sudo-1.9.12p1.tar.gz) = 475a18a8eb3da8b2917ceab063a6baf51ea09128c3c47e3e0e33ab7497bab7d8 -SIZE (sudo-1.9.12p1.tar.gz) = 4908060 +TIMESTAMP = 1674058310 +SHA256 (sudo-1.9.12p2.tar.gz) = b9a0b1ae0f1ddd9be7f3eafe70be05ee81f572f6f536632c44cd4101bb2a8539 +SIZE (sudo-1.9.12p2.tar.gz) = 4909431