[arch-dev-public] [signoff] sudo-1.7.4.p4

Allan McRae allan at archlinux.org
Thu Sep 9 01:30:07 EDT 2010


Upstream security fix release:

This release fixes a security issue with respect to the handling
of sudo's -g command line option when -u is also specified.  The
flaw may allow an attacker to run commands as a user that is not
authorized by the sudoers file.  For more details, see:
     http://www.sudo.ws/sudo/alerts/runas_group.html

Some quick signoffs would be good...

Signoff both,
Allan





More information about the arch-dev-public mailing list