Re: [arch-dev-public] [signoff] sudo-1.7.4.p4

2010-09-09 Thread Guillaume ALAUX
On 9 September 2010 07:30, Allan McRae al...@archlinux.org wrote:
 Upstream security fix release:

 This release fixes a security issue with respect to the handling
 of sudo's -g command line option when -u is also specified.  The
 flaw may allow an attacker to run commands as a user that is not
 authorized by the sudoers file.  For more details, see:
    http://www.sudo.ws/sudo/alerts/runas_group.html

 Some quick signoffs would be good...

 Signoff both,
 Allan

signoff i686

--
Guillaume


--
Guillaume


Re: [arch-dev-public] [signoff] sudo-1.7.4.p4

2010-09-09 Thread Eric Bélanger
On Thu, Sep 9, 2010 at 1:30 AM, Allan McRae al...@archlinux.org wrote:
 Upstream security fix release:

 This release fixes a security issue with respect to the handling
 of sudo's -g command line option when -u is also specified.  The
 flaw may allow an attacker to run commands as a user that is not
 authorized by the sudoers file.  For more details, see:
    http://www.sudo.ws/sudo/alerts/runas_group.html

 Some quick signoffs would be good...

 Signoff both,
 Allan





signoff x86_64


[arch-dev-public] [signoff] sudo-1.7.4.p4

2010-09-08 Thread Allan McRae

Upstream security fix release:

This release fixes a security issue with respect to the handling
of sudo's -g command line option when -u is also specified.  The
flaw may allow an attacker to run commands as a user that is not
authorized by the sudoers file.  For more details, see:
http://www.sudo.ws/sudo/alerts/runas_group.html

Some quick signoffs would be good...

Signoff both,
Allan