Debian Bug report logs - #349196
sudo: DSA-946-1 broke joe horribly

version graph

Package: sudo; Maintainer for sudo is Bdale Garbee <>; Source for sudo is src:sudo.

Reported by: Josip Rodin <>

Date: Sat, 21 Jan 2006 14:03:05 UTC

Severity: critical

Tags: patch

Merged with 349549, 349587, 349729

Found in version sudo/1.6.8p7-1.3

Fixed in version sudo/1.6.8p12-2

Done: Steve Langasek <>

Bug is archived. No further changes may be made.

Full log

Message #43 received at (full text, mbox):

Received: (at 349196) by; 3 Mar 2006 11:18:12 +0000
From Fri Mar 03 03:18:12 2006
Return-path: <>
Received: from ([])
	by with esmtp (Exim 4.50)
	id 1FF8IW-00017t-HY; Fri, 03 Mar 2006 03:18:12 -0800
Received: from ([]
	by with esmtps (TLS-1.0:RSA_AES_256_CBC_SHA:32)
	(Exim 4.50)
	id 1FF8IT-0004lG-Bh; Fri, 03 Mar 2006 12:18:09 +0100
Received: from jeroen by with local (Exim 4.50)
	id 1FF8IT-0001UG-7u; Fri, 03 Mar 2006 12:18:09 +0100
Date: Fri, 3 Mar 2006 12:18:09 +0100
To: Mikko Rapeli <>,,
	Debian Bugs Control Bot <>
Subject: Re: a fix for sudo in sarge
Message-ID: <>
References: <>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <>
User-Agent: Mutt/1.5.9i
From: Jeroen van Wolffelaar <>
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
	(1.212-2003-09-23-exp) on
X-Spam-Status: No, hits=-5.0 required=4.0 tests=BAYES_00,VALID_BTS_CONTROL 
	autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-CrossAssassin-Score: 2
tags 349196 + patch

On Thu, Feb 09, 2006 at 05:28:30PM +0200, Mikko Rapeli wrote:
> This seems to work and allows me to use ethereal remotely through ssh again.
> The for loop was just copied from above and keepit changed to okvar, so this is
> pretty simple. We did go through all the bits and if clauses and tested the
> result manually. The manual page changes are pretty obvious too.
> I did not go through the list of environment variables mentioned on 
> manual pages and 'sudo -V' when run as root, but perhaps the documentation
> is enough as this is only first aid for sarge.

Thank you for preparing a patch.

Bdale, Security team, what do you think about it?


Jeroen van Wolffelaar

Send a report that this bug log contains spam.

Debian bug tracking system administrator <>. Last modified: Wed Apr 16 11:02:56 2014; Machine Name:

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.