Oval Definition:
oval:org.opensuse.security:def:68440
Revision Date
:
2020-12-01
Version
:
1
Title
:
Security update for sudo (Important)
Description
:
This update for sudo fixes the following issues:
Security issue fixed:
- CVE-2019-18634: Fixed a buffer overflow in the passphrase prompt that could occur when pwfeedback was enabled in /etc/sudoers (bsc#1162202).
Non-security issue fixed:
- Fixed an issue where sudo -l would ask for a password even though `listpw` was set to `never` (bsc#1162675).
Family
:
unix
Class
:
patch
Status
:
Reference(s)
:
1162202
1162675
1170603
CVE-2019-18634
CVE-2020-12268
SUSE-SU-2020:0408-1
SUSE-SU-2020:1220-1
Platform(s)
:
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Module for Desktop Applications 15 SP1
Product(s)
:
Definition Synopsis
SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
AND
Package Information
sudo-1.8.22-4.9 is installed
OR
sudo-devel-1.8.22-4.9 is installed
Definition Synopsis
SUSE Linux Enterprise Module for Desktop Applications 15 SP1 is installed
AND
Package Information
libspectre-0.2.8-3.10 is installed
OR
libspectre-devel-0.2.8-3.10 is installed
OR
libspectre1-0.2.8-3.10 is installed
BACK