Author: renodr
Date: Tue Oct 15 20:30:42 2019
New Revision: 1502
Log:
Add errata for sudo vulnerability and fix ghostscript errata in systemd
Modified:
html/trunk/blfs/errata/9.0-systemd/index.html
html/trunk/blfs/errata/9.0/index.html
Modified: html/trunk/blfs/errata/9.0-systemd/index.html
==============================================================================
--- html/trunk/blfs/errata/9.0-systemd/index.html Tue Oct 15 20:04:51
2019 (r1501)
+++ html/trunk/blfs/errata/9.0-systemd/index.html Tue Oct 15 20:30:42
2019 (r1502)
@@ -106,8 +106,12 @@
PDF documents can access the filesystem outside of restricted areas
and execute arbitrary commands. To fix these vulnerabilities, apply
the updated "-2" patch found in
- <a href="../../view/svn/pst/ghostscript.html">ghostscript-9.27</a>.</p>
+ <a
href="../../view/systemd/pst/ghostscript.html">ghostscript-9.27</a>.</p>
+ <p>After release, a potential restriction bypass vulnerability was
+ discovered in Sudo prior to version 1.8.28. To fix this, update to
+ Sudo-1.8.28 ASAP using the instructions in
+ <a href="../../view/systemd/postlfs/sudo.html">sudo-1.8.28</a>.</p>
<h2>Known Security Vulnerabilities</h2>
Modified: html/trunk/blfs/errata/9.0/index.html
==============================================================================
--- html/trunk/blfs/errata/9.0/index.html Tue Oct 15 20:04:51 2019
(r1501)
+++ html/trunk/blfs/errata/9.0/index.html Tue Oct 15 20:30:42 2019
(r1502)
@@ -113,6 +113,11 @@
the updated "-2" patch found in
<a href="../../view/svn/pst/ghostscript.html">ghostscript-9.27</a>.</p>
+ <p>After release, a potential restriction bypass vulnerability was
+ discovered in Sudo prior to version 1.8.28. To fix this, update to
+ Sudo-1.8.28 ASAP using the instructions in
+ <a href="../../view/svn/postlfs/sudo.html">sudo-1.8.28</a>.</p>
+
<!--
<p>A vulnerability with available exploits in all recent versions of
ghostscript has been fixed in the development book by patching gs-9.25.
--
http://lists.linuxfromscratch.org/listinfo/website
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page