Univention Bugzilla – Bug 37853
sudo: Missing environment sanitising (3.2)
Last modified: 2015-05-07 13:47:14 CEST
+++ This bug was initially created as a clone of Bug #37852 +++ CVE-2014-9680: Arbitrary file access via user defined TZ environment variable
Ticket#2015040721000323 Customer (with ES) requested this fix.
Upstream package version 1.7.4p4-2.squeeze.5 imported and built in errata3.2-5. Also fixes CVE-2014-0106 (see Bug 34270) Advisory: 2015-04-08-sudo.yaml
Changelog: OK Tests: OK Advisory: OK
<http://errata.univention.de/ucs/3.2/327.html>