Univention Bugzilla – Bug 37852
sudo: Missing environment sanitising (4.0)
Last modified: 2015-05-07 17:45:23 CEST
CVE-2014-9680: Arbitrary file access via user defined TZ environment variable
Upstream package version 1.8.5p2-1+nmu2 imported and built in errata4.0-1. Also fixes CVE-2014-0106 (see Bug 34270) Advisory: 2015-04-08-sudo.yaml
Advisory: OK Tests (i386): OK Changelog: OK
<http://errata.univention.de/ucs/4.0/165.html>