[arch-dev-public] [signoff] sudo-1.7.4.p4
Allan McRae
allan at archlinux.org
Thu Sep 9 01:30:07 EDT 2010
Upstream security fix release:
This release fixes a security issue with respect to the handling
of sudo's -g command line option when -u is also specified. The
flaw may allow an attacker to run commands as a user that is not
authorized by the sudoers file. For more details, see:
http://www.sudo.ws/sudo/alerts/runas_group.html
Some quick signoffs would be good...
Signoff both,
Allan
More information about the arch-dev-public
mailing list