diff options
author | Praveen Kumar <praveen.kumar@windriver.com> | 2025-07-11 21:39:18 +0530 |
---|---|---|
committer | Steve Sakoman <steve@sakoman.com> | 2025-07-21 09:07:22 -0700 |
commit | a27ca8e3c08545f86f301013baec1f52533b816a (patch) | |
tree | fb9ced9ec5b535c2f12714b43c032e95e04db7d4 /scripts/pybootchartgui/pybootchartgui.py | |
parent | 38f0ee2ec7ce03f802aefb613e8b34259f0c0dfc (diff) | |
download | poky-a27ca8e3c08545f86f301013baec1f52533b816a.tar.gz |
sudo: upgrade 1.9.15p5 -> 1.9.17p1
Changelog:
===========
* Fixed CVE-2025-32462. Sudo's -h (--host) option could be specified
when running a command or editing a file. This could enable a
local privilege escalation attack if the sudoers file allows the
user to run commands on a different host.
* Fixed CVE-2025-32463. An attacker can leverage sudo's -R
(--chroot) option to run arbitrary commands as root, even if
they are not listed in the sudoers file. The chroot support has
been deprecated an will be removed entirely in a future release.
License-Update: Copyright updated to 2025
0001-sudo.conf.in-fix-conflict-with-multilib.patch refreshed for 1.9.17
(From OE-Core rev: b04af6db102c97f3d4338dbcfdcab927b5194a69)
Signed-off-by: Praveen Kumar <praveen.kumar@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'scripts/pybootchartgui/pybootchartgui.py')
0 files changed, 0 insertions, 0 deletions