Pullup ticket 140 - requested by Quentin Garnier
authorsalo <salo>
Mon, 15 Nov 2004 08:02:54 +0000 (08:02 +0000)
committersalo <salo>
Mon, 15 Nov 2004 08:02:54 +0000 (08:02 +0000)
commit621484178090e6b2a30992db1c5dfa47e72ab432
treec9bb4cd6a18f23cf3f0e762a52b6e88abe98f19a
parent1e27eab416528a25a06ae1948275976014c78206
Pullup ticket 140 - requested by Quentin Garnier
security fix for sudo

        Module Name: pkgsrc
        Committed By: cube
        Date: Fri Nov 12 16:47:31 UTC 2004

        Modified Files:
         pkgsrc/security/sudo: Makefile PLIST.NetBSD PLIST.SunOS distinfo

        Log Message:
        Update to version 1.6.8pl2.  Fixes a security flaw for the sad people using
        bash-as-sh (and people allowing bash scripts to be run through sudo).  The
        user could override commands by functions of her own.

        ChangeLog:

        549) Bash exported functions and the CDPATH variable are now stripped from
             the environment passed to the program to be executed.
security/sudo/Makefile
security/sudo/PLIST.NetBSD
security/sudo/PLIST.SunOS
security/sudo/distinfo