Report forwarded to debian-bugs-dist@lists.debian.org, Bdale Garbee <bdale@gag.com>:
Bug#85123; Package sudo.   debian-bugs-dist@lists.debian.orgBdale Garbee  Subject: Bug#85123: sudo: SECURE_PATH still can't be overridden Reply-To: , 85123@bugs.debian.org Resent-From: Resent-To: debian-bugs-dist@lists.debian.org Resent-CC: Bdale Garbee Resent-Date: Wed, 07 Feb 2001 01:48:02 GMT Resent-Message-ID: Resent-Sender: owner@bugs.debian.org X-Debian-PR-Message: report 85123 X-Debian-PR-Package: sudo X-Debian-PR-Keywords: X-Loop: owner@bugs.debian.org Received: via spool by bugs@bugs.debian.org id=B.98150985924884 (code B ref -1); Wed, 07 Feb 2001 01:48:02 GMT Date: Wed, 7 Feb 2001 12:37:31 +1100 Message-Id: <200102070137.f171bV024471@gondor.apana.org.au> From: To: submit@bugs.debian.org X-Mailer: bug 3.3.7 Delivered-To: submit@bugs.debian.org Package: sudo Version: 1.6.3p5-1 Severity: normal It seems that Bug#20996 is still present in this version of sudo. The changelog says that it can be overridden at runtime but I haven't yet discovered how. -- System Information Debian Release: testing/unstable Kernel Version: Linux gondor 2.2.17 #1 Mon Sep 11 22:22:16 EST 2000 i586 unknown Versions of the packages sudo depends on: ii libc6 2.2.1-1 GNU C Library: Shared libraries and Timezone ii libpam-modules 0.72-12 Pluggable Authentication Modules for PAM ii libpam0g 0.72-12 Pluggable Authentication Modules library   Acknowledgement sent to <herbert@gondor.apana.org.au>:
New Bug report received and forwarded. Copy sent to Bdale Garbee <bdale@gag.com>.   -t  From: owner@bugs.debian.org (Debian Bug Tracking System) To: Subject: Bug#85123: Acknowledgement (sudo: SECURE_PATH still can't be overridden) Message-ID: In-Reply-To: <200102070137.f171bV024471@gondor.apana.org.au> References: <200102070137.f171bV024471@gondor.apana.org.au> X-Debian-PR-Message: ack 85123 Thank you for the problem report you have sent regarding Debian. This is an automatically generated reply, to let you know your message has been received. It is being forwarded to the developers mailing list for their attention; they will reply in due course. Your message has been sent to the package maintainer(s): Bdale Garbee If you wish to submit further information on your problem, please send it to 85123@bugs.debian.org (and *not* to bugs@bugs.debian.org). Please do not reply to the address at the top of this message, unless you wish to report a problem with the Bug-tracking system. Darren Benham (administrator, Debian Bugs database)   Received: (at submit) by bugs.debian.org; 7 Feb 2001 01:37:39 +0000 From herbert@gondor.apana.org.au Tue Feb 06 19:37:39 2001 Return-path: Received: from gondor.apana.org.au [::ffff:203.14.152.114] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14QJY9-0006RK-00; Tue, 06 Feb 2001 19:37:38 -0600 Received: (from herbert@localhost) by gondor.apana.org.au (8.11.1/8.11.1/Debian 8.11.0-6) id f171bV024471; Wed, 7 Feb 2001 12:37:31 +1100 Date: Wed, 7 Feb 2001 12:37:31 +1100 Message-Id: <200102070137.f171bV024471@gondor.apana.org.au> From: Subject: sudo: SECURE_PATH still can't be overridden To: submit@bugs.debian.org X-Mailer: bug 3.3.7 Delivered-To: submit@bugs.debian.org Package: sudo Version: 1.6.3p5-1 Severity: normal It seems that Bug#20996 is still present in this version of sudo. The changelog says that it can be overridden at runtime but I haven't yet discovered how. -- System Information Debian Release: testing/unstable Kernel Version: Linux gondor 2.2.17 #1 Mon Sep 11 22:22:16 EST 2000 i586 unknown Versions of the packages sudo depends on: ii libc6 2.2.1-1 GNU C Library: Shared libraries and Timezone ii libpam-modules 0.72-12 Pluggable Authentication Modules for PAM ii libpam0g 0.72-12 Pluggable Authentication Modules library   Reply sent to Bdale Garbee <bdale@gag.com>:
You have taken responsibility.   -t  From: owner@bugs.debian.org (Debian Bug Tracking System) To: Bdale Garbee Bcc: debian-bugs-closed@lists.debian.org Subject: Bug#85123: marked as done (sudo: SECURE_PATH still can't be overridden) Message-ID: In-Reply-To: <87vgqnukwx.fsf@rover.gag.com> References: <87vgqnukwx.fsf@rover.gag.com> <200102070137.f171bV024471@gondor.apana.org.au> X-Debian-PR-Message: closed 85123 Your message dated 06 Feb 2001 22:22:38 -0700 with message-id <87vgqnukwx.fsf@rover.gag.com> and subject line Bug#85123: sudo: SECURE_PATH still can't be overridden has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what I am talking about this indicates a serious mail system misconfiguration somewhere. Please contact me immediately.) Darren Benham (administrator, Debian Bugs database) -------------------------------------- Received: (at submit) by bugs.debian.org; 7 Feb 2001 01:37:39 +0000 From herbert@gondor.apana.org.au Tue Feb 06 19:37:39 2001 Return-path: Received: from gondor.apana.org.au [::ffff:203.14.152.114] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14QJY9-0006RK-00; Tue, 06 Feb 2001 19:37:38 -0600 Received: (from herbert@localhost) by gondor.apana.org.au (8.11.1/8.11.1/Debian 8.11.0-6) id f171bV024471; Wed, 7 Feb 2001 12:37:31 +1100 Date: Wed, 7 Feb 2001 12:37:31 +1100 Message-Id: <200102070137.f171bV024471@gondor.apana.org.au> From: Subject: sudo: SECURE_PATH still can't be overridden To: submit@bugs.debian.org X-Mailer: bug 3.3.7 Delivered-To: submit@bugs.debian.org Package: sudo Version: 1.6.3p5-1 Severity: normal It seems that Bug#20996 is still present in this version of sudo. The changelog says that it can be overridden at runtime but I haven't yet discovered how. -- System Information Debian Release: testing/unstable Kernel Version: Linux gondor 2.2.17 #1 Mon Sep 11 22:22:16 EST 2000 i586 unknown Versions of the packages sudo depends on: ii libc6 2.2.1-1 GNU C Library: Shared libraries and Timezone ii libpam-modules 0.72-12 Pluggable Authentication Modules for PAM ii libpam0g 0.72-12 Pluggable Authentication Modules library --------------------------------------- Received: (at 85123-done) by bugs.debian.org; 7 Feb 2001 05:22:43 +0000 From bdale@gag.com Tue Feb 06 23:22:43 2001 Return-path: Received: from winfree.gag.com [::ffff:192.133.104.8] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14QN3z-0004wa-00; Tue, 06 Feb 2001 23:22:43 -0600 Received: from rover.gag.com (rover.gag.com [192.133.104.32]) by winfree.gag.com (Postfix) with ESMTP id 47D02266E8; Tue, 6 Feb 2001 22:22:39 -0700 (MST) Received: by rover.gag.com (Postfix, from userid 1000) id 754C836319; Tue, 6 Feb 2001 22:22:38 -0700 (MST) Sender: bdale@rover.gag.com To: , 85123-done@bugs.debian.org Subject: Re: Bug#85123: sudo: SECURE_PATH still can't be overridden References: <200102070137.f171bV024471@gondor.apana.org.au> From: Bdale Garbee Date: 06 Feb 2001 22:22:38 -0700 In-Reply-To: herbert@gondor.apana.org.au's message of "6 Feb 2001 18:48:20 -0700" Message-ID: <87vgqnukwx.fsf@rover.gag.com> Lines: 20 User-Agent: Gnus/5.0807 (Gnus v5.8.7) XEmacs/21.1 (Crater Lake) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Delivered-To: 85123-done@bugs.debian.org herbert@gondor.apana.org.au writes: > Package: sudo > Version: 1.6.3p5-1 > Severity: normal > > It seems that Bug#20996 is still present in this version of sudo. The > changelog says that it can be overridden at runtime but I haven't yet > discovered how. Have you read the sudoers man page? There is now a config file option secure_path that can be used in various ways, including something like: Defaults syslog=auth, secure_path="/bin:/usr/bin:/usr/local/bin" Of course, that's not a very sane PATH, but you get the idea. Bdale   Notification sent to <herbert@gondor.apana.org.au>:
Bug acknowledged by developer.   -t  From: owner@bugs.debian.org (Debian Bug Tracking System) To: Subject: Bug#85123 acknowledged by developer (Re: Bug#85123: sudo: SECURE_PATH still can't be overridden) Message-ID: In-Reply-To: <200102070137.f171bV024471@gondor.apana.org.au> References: <87vgqnukwx.fsf@rover.gag.com> <200102070137.f171bV024471@gondor.apana.org.au> X-Debian-PR-Message: they-closed 85123 This is an automatic notification regarding your Bug report #85123: sudo: SECURE_PATH still can't be overridden, which was filed against the sudo package. It has been closed by one of the developers, namely Bdale Garbee . Their explanation is attached below. If this explanation is unsatisfactory and you have not received a better one in a separate message then please contact the developer directly, or email 85123@bugs.debian.org or me. Darren Benham (administrator, Debian Bugs database) Received: (at 85123-done) by bugs.debian.org; 7 Feb 2001 05:22:43 +0000 From bdale@gag.com Tue Feb 06 23:22:43 2001 Return-path: Received: from winfree.gag.com [::ffff:192.133.104.8] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14QN3z-0004wa-00; Tue, 06 Feb 2001 23:22:43 -0600 Received: from rover.gag.com (rover.gag.com [192.133.104.32]) by winfree.gag.com (Postfix) with ESMTP id 47D02266E8; Tue, 6 Feb 2001 22:22:39 -0700 (MST) Received: by rover.gag.com (Postfix, from userid 1000) id 754C836319; Tue, 6 Feb 2001 22:22:38 -0700 (MST) Sender: bdale@rover.gag.com To: , 85123-done@bugs.debian.org Subject: Re: Bug#85123: sudo: SECURE_PATH still can't be overridden References: <200102070137.f171bV024471@gondor.apana.org.au> From: Bdale Garbee Date: 06 Feb 2001 22:22:38 -0700 In-Reply-To: herbert@gondor.apana.org.au's message of "6 Feb 2001 18:48:20 -0700" Message-ID: <87vgqnukwx.fsf@rover.gag.com> Lines: 20 User-Agent: Gnus/5.0807 (Gnus v5.8.7) XEmacs/21.1 (Crater Lake) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Delivered-To: 85123-done@bugs.debian.org herbert@gondor.apana.org.au writes: > Package: sudo > Version: 1.6.3p5-1 > Severity: normal > > It seems that Bug#20996 is still present in this version of sudo. The > changelog says that it can be overridden at runtime but I haven't yet > discovered how. Have you read the sudoers man page? There is now a config file option secure_path that can be used in various ways, including something like: Defaults syslog=auth, secure_path="/bin:/usr/bin:/usr/local/bin" Of course, that's not a very sane PATH, but you get the idea. Bdale   Received: (at 85123-done) by bugs.debian.org; 7 Feb 2001 05:22:43 +0000 From bdale@gag.com Tue Feb 06 23:22:43 2001 Return-path: Received: from winfree.gag.com [::ffff:192.133.104.8] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14QN3z-0004wa-00; Tue, 06 Feb 2001 23:22:43 -0600 Received: from rover.gag.com (rover.gag.com [192.133.104.32]) by winfree.gag.com (Postfix) with ESMTP id 47D02266E8; Tue, 6 Feb 2001 22:22:39 -0700 (MST) Received: by rover.gag.com (Postfix, from userid 1000) id 754C836319; Tue, 6 Feb 2001 22:22:38 -0700 (MST) Sender: bdale@rover.gag.com To: , 85123-done@bugs.debian.org Subject: Re: Bug#85123: sudo: SECURE_PATH still can't be overridden References: <200102070137.f171bV024471@gondor.apana.org.au> From: Bdale Garbee Date: 06 Feb 2001 22:22:38 -0700 In-Reply-To: herbert@gondor.apana.org.au's message of "6 Feb 2001 18:48:20 -0700" Message-ID: <87vgqnukwx.fsf@rover.gag.com> Lines: 20 User-Agent: Gnus/5.0807 (Gnus v5.8.7) XEmacs/21.1 (Crater Lake) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Delivered-To: 85123-done@bugs.debian.org herbert@gondor.apana.org.au writes: > Package: sudo > Version: 1.6.3p5-1 > Severity: normal > > It seems that Bug#20996 is still present in this version of sudo. The > changelog says that it can be overridden at runtime but I haven't yet > discovered how. Have you read the sudoers man page? There is now a config file option secure_path that can be used in various ways, including something like: Defaults syslog=auth, secure_path="/bin:/usr/bin:/usr/local/bin" Of course, that's not a very sane PATH, but you get the idea. Bdale   Information forwarded to debian-bugs-dist@lists.debian.org, Bdale Garbee <bdale@gag.com>:
Bug#85123; Package sudo.   debian-bugs-dist@lists.debian.orgBdale Garbee  Subject: Bug#85123: sudo: SECURE_PATH still can't be overridden Reply-To: Herbert Xu , 85123@bugs.debian.org Resent-From: Herbert Xu Resent-To: debian-bugs-dist@lists.debian.org Resent-CC: Bdale Garbee Resent-Date: Wed, 07 Feb 2001 08:04:00 GMT Resent-Message-ID: Resent-Sender: owner@bugs.debian.org X-Debian-PR-Message: report 85123 X-Debian-PR-Package: sudo X-Debian-PR-Keywords: X-Loop: owner@bugs.debian.org Received: via spool by 85123-bugs@bugs.debian.org id=B85123.98153220523013 (code B ref 85123); Wed, 07 Feb 2001 08:04:00 GMT From: Herbert Xu Date: Wed, 7 Feb 2001 18:49:57 +1100 To: 85123@bugs.debian.org Message-ID: <20010207184957.A27841@gondor.apana.org.au> References: <200102070137.f171bV024471@gondor.apana.org.au> <87vgqnukwx.fsf@rover.gag.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.3.12i In-Reply-To: <87vgqnukwx.fsf@rover.gag.com>; from bdale@gag.com on Tue, Feb 06, 2001 at 10:22:38PM -0700 Delivered-To: 85123@bugs.debian.org reopen 85123 quit On Tue, Feb 06, 2001 at 10:22:38PM -0700, Bdale Garbee wrote: > herbert@gondor.apana.org.au writes: > > > Package: sudo > > Version: 1.6.3p5-1 > > Severity: normal > > > > It seems that Bug#20996 is still present in this version of sudo. The > > changelog says that it can be overridden at runtime but I haven't yet > > discovered how. > > Have you read the sudoers man page? > > There is now a config file option secure_path that can be used in various > ways, including something like: > > Defaults syslog=auth, secure_path="/bin:/usr/bin:/usr/local/bin" > > Of course, that's not a very sane PATH, but you get the idea. Sorry, I wasn't very clear in the report. What I want to do is to turn off secure_path. That is, I need to preserve the user's PATH. -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt   Acknowledgement sent to Herbert Xu <herbert@gondor.apana.org.au>:
Extra info received and forwarded to list. Copy sent to Bdale Garbee <bdale@gag.com>.   -t  From: owner@bugs.debian.org (Debian Bug Tracking System) To: Herbert Xu Subject: Bug#85123: Info received (was Bug#85123: sudo: SECURE_PATH still can't be overridden) Message-ID: In-Reply-To: <20010207184957.A27841@gondor.apana.org.au> References: <20010207184957.A27841@gondor.apana.org.au> X-Debian-PR-Message: ack-info-maintonly 85123 Thank you for the additional information you have supplied regarding this problem report. It has been forwarded to the developer(s) and to the developers mailing list to accompany the original report. Your message has been sent to the package maintainer(s): Bdale Garbee If you wish to continue to submit further information on your problem, please send it to 85123@bugs.debian.org, as before. Please do not reply to the address at the top of this message, unless you wish to report a problem with the Bug-tracking system. Darren Benham (administrator, Debian Bugs database)   Received: (at 85123) by bugs.debian.org; 7 Feb 2001 07:50:05 +0000 From herbert@gondor.apana.org.au Wed Feb 07 01:50:05 2001 Return-path: Received: from gondor.apana.org.au [::ffff:203.14.152.114] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14QPMY-0005yv-00; Wed, 07 Feb 2001 01:50:04 -0600 Received: (from herbert@localhost) by gondor.apana.org.au (8.11.1/8.11.1/Debian 8.11.0-6) id f177nvD27949; Wed, 7 Feb 2001 18:49:57 +1100 From: Herbert Xu Date: Wed, 7 Feb 2001 18:49:57 +1100 To: 85123@bugs.debian.org Subject: Re: Bug#85123: sudo: SECURE_PATH still can't be overridden Message-ID: <20010207184957.A27841@gondor.apana.org.au> References: <200102070137.f171bV024471@gondor.apana.org.au> <87vgqnukwx.fsf@rover.gag.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.3.12i In-Reply-To: <87vgqnukwx.fsf@rover.gag.com>; from bdale@gag.com on Tue, Feb 06, 2001 at 10:22:38PM -0700 Delivered-To: 85123@bugs.debian.org reopen 85123 quit On Tue, Feb 06, 2001 at 10:22:38PM -0700, Bdale Garbee wrote: > herbert@gondor.apana.org.au writes: > > > Package: sudo > > Version: 1.6.3p5-1 > > Severity: normal > > > > It seems that Bug#20996 is still present in this version of sudo. The > > changelog says that it can be overridden at runtime but I haven't yet > > discovered how. > > Have you read the sudoers man page? > > There is now a config file option secure_path that can be used in various > ways, including something like: > > Defaults syslog=auth, secure_path="/bin:/usr/bin:/usr/local/bin" > > Of course, that's not a very sane PATH, but you get the idea. Sorry, I wasn't very clear in the report. What I want to do is to turn off secure_path. That is, I need to preserve the user's PATH. -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt   Bug reopened, originator not changed. Request was from Herbert Xu <herbert@gondor.apana.org.au> to control@bugs.debian.org.   Received: (at control) by bugs.debian.org; 7 Feb 2001 07:50:05 +0000 From herbert@gondor.apana.org.au Wed Feb 07 01:50:05 2001 Return-path: Received: from gondor.apana.org.au [::ffff:203.14.152.114] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14QPMY-0005yv-00; Wed, 07 Feb 2001 01:50:04 -0600 Received: (from herbert@localhost) by gondor.apana.org.au (8.11.1/8.11.1/Debian 8.11.0-6) id f177nvD27949; Wed, 7 Feb 2001 18:49:57 +1100 From: Herbert Xu Date: Wed, 7 Feb 2001 18:49:57 +1100 To: 85123@bugs.debian.org Subject: Re: Bug#85123: sudo: SECURE_PATH still can't be overridden Message-ID: <20010207184957.A27841@gondor.apana.org.au> References: <200102070137.f171bV024471@gondor.apana.org.au> <87vgqnukwx.fsf@rover.gag.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.3.12i In-Reply-To: <87vgqnukwx.fsf@rover.gag.com>; from bdale@gag.com on Tue, Feb 06, 2001 at 10:22:38PM -0700 Delivered-To: control@bugs.debian.org reopen 85123 quit On Tue, Feb 06, 2001 at 10:22:38PM -0700, Bdale Garbee wrote: > herbert@gondor.apana.org.au writes: > > > Package: sudo > > Version: 1.6.3p5-1 > > Severity: normal > > > > It seems that Bug#20996 is still present in this version of sudo. The > > changelog says that it can be overridden at runtime but I haven't yet > > discovered how. > > Have you read the sudoers man page? > > There is now a config file option secure_path that can be used in various > ways, including something like: > > Defaults syslog=auth, secure_path="/bin:/usr/bin:/usr/local/bin" > > Of course, that's not a very sane PATH, but you get the idea. Sorry, I wasn't very clear in the report. What I want to do is to turn off secure_path. That is, I need to preserve the user's PATH. -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt   Severity set to `wishlist'. Request was from bdale@gag.com (Bdale Garbee) to control@bugs.debian.org.   Received: (at control) by bugs.debian.org; 7 Feb 2001 08:17:29 +0000 From bdale@gag.com Wed Feb 07 02:17:29 2001 Return-path: Received: from winfree.gag.com [::ffff:192.133.104.8] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14QPn6-0007kd-00; Wed, 07 Feb 2001 02:17:29 -0600 Received: from rover.gag.com (rover.gag.com [192.133.104.32]) by winfree.gag.com (Postfix) with ESMTP id ACE8F242A2 for ; Wed, 7 Feb 2001 01:17:26 -0700 (MST) Received: by rover.gag.com (Postfix, from userid 1000) id 51BA036319; Wed, 7 Feb 2001 01:17:26 -0700 (MST) To: control@bugs.debian.org Subject: maybe someday... Message-Id: <20010207081726.51BA036319@rover.gag.com> Date: Wed, 7 Feb 2001 01:17:26 -0700 (MST) From: bdale@gag.com (Bdale Garbee) Delivered-To: control@bugs.debian.org severity 85123 wishlist   Information forwarded to debian-bugs-dist@lists.debian.org:
Bug#85123; Package sudo.   debian-bugs-dist@lists.debian.org  Subject: Bug#85123: sudo: SECURE_PATH still can't be overridden Reply-To: Bdale Garbee , 85123@bugs.debian.org Resent-From: Bdale Garbee Orignal-Sender: bdale@rover.gag.com Resent-To: debian-bugs-dist@lists.debian.org Resent-Date: Wed, 07 Feb 2001 08:33:10 GMT Resent-Message-ID: Resent-Sender: owner@bugs.debian.org X-Debian-PR-Message: report 85123 X-Debian-PR-Package: sudo X-Debian-PR-Keywords: X-Loop: owner@bugs.debian.org Received: via spool by 85123-bugs@bugs.debian.org id=B85123.98153396430134 (code B ref 85123); Wed, 07 Feb 2001 08:33:10 GMT Sender: bdale@rover.gag.com To: Herbert Xu , 85123@bugs.debian.org References: <200102070137.f171bV024471@gondor.apana.org.au> <20010207184957.A27841@gondor.apana.org.au> From: Bdale Garbee Date: 07 Feb 2001 01:19:22 -0700 In-Reply-To: herbert@gondor.apana.org.au's message of "7 Feb 2001 01:04:03 -0700" Message-ID: <877l326h2t.fsf@rover.gag.com> Lines: 14 User-Agent: Gnus/5.0807 (Gnus v5.8.7) XEmacs/21.1 (Crater Lake) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Delivered-To: 85123@bugs.debian.org herbert@gondor.apana.org.au (Herbert Xu) writes: > Sorry, I wasn't very clear in the report. What I want to do is to turn > off secure_path. That is, I need to preserve the user's PATH. Now that the secure path option is available at runtime, I may perhaps change the default in a future upload to not use this option and instead provide boilerplate for it in the example sudoers file... In the meantime, I'm classifying this as wishlist, since the current behavior is intentional. > -- > Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) > Email: Herbert Xu ~{PmV>HI~} > Home Page: http://gondor.apana.org.au/~herbert/ > PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt   Acknowledgement sent to Bdale Garbee <bdale@gag.com>:
Extra info received and forwarded to list.   -t  From: owner@bugs.debian.org (Debian Bug Tracking System) To: Bdale Garbee Subject: Bug#85123: Info received (was Bug#85123: sudo: SECURE_PATH still can't be overridden) Message-ID: In-Reply-To: <877l326h2t.fsf@rover.gag.com> References: <877l326h2t.fsf@rover.gag.com> X-Debian-PR-Message: ack-info-maintonly 85123 Thank you for the additional information you have supplied regarding this problem report. It has been forwarded to the developer(s) and to the developers mailing list to accompany the original report. If you wish to continue to submit further information on your problem, please send it to 85123@bugs.debian.org, as before. Please do not reply to the address at the top of this message, unless you wish to report a problem with the Bug-tracking system. Darren Benham (administrator, Debian Bugs database)   Received: (at 85123) by bugs.debian.org; 7 Feb 2001 08:19:24 +0000 From bdale@gag.com Wed Feb 07 02:19:23 2001 Return-path: Received: from winfree.gag.com [::ffff:192.133.104.8] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14QPox-0007pz-00; Wed, 07 Feb 2001 02:19:23 -0600 Received: from rover.gag.com (rover.gag.com [192.133.104.32]) by winfree.gag.com (Postfix) with ESMTP id 2D931242A2; Wed, 7 Feb 2001 01:19:23 -0700 (MST) Received: by rover.gag.com (Postfix, from userid 1000) id C2BE136319; Wed, 7 Feb 2001 01:19:22 -0700 (MST) Sender: bdale@rover.gag.com To: Herbert Xu , 85123@bugs.debian.org Subject: Re: Bug#85123: sudo: SECURE_PATH still can't be overridden References: <200102070137.f171bV024471@gondor.apana.org.au> <20010207184957.A27841@gondor.apana.org.au> From: Bdale Garbee Date: 07 Feb 2001 01:19:22 -0700 In-Reply-To: herbert@gondor.apana.org.au's message of "7 Feb 2001 01:04:03 -0700" Message-ID: <877l326h2t.fsf@rover.gag.com> Lines: 14 User-Agent: Gnus/5.0807 (Gnus v5.8.7) XEmacs/21.1 (Crater Lake) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Delivered-To: 85123@bugs.debian.org herbert@gondor.apana.org.au (Herbert Xu) writes: > Sorry, I wasn't very clear in the report. What I want to do is to turn > off secure_path. That is, I need to preserve the user's PATH. Now that the secure path option is available at runtime, I may perhaps change the default in a future upload to not use this option and instead provide boilerplate for it in the example sudoers file... In the meantime, I'm classifying this as wishlist, since the current behavior is intentional. > -- > Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) > Email: Herbert Xu ~{PmV>HI~} > Home Page: http://gondor.apana.org.au/~herbert/ > PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt   Reply sent to Bdale Garbee <bdale@gag.com>:
You have taken responsibility.   -t  From: owner@bugs.debian.org (Debian Bug Tracking System) To: Bdale Garbee Bcc: debian-bugs-closed@lists.debian.org Subject: Bug#85123: marked as done (sudo: SECURE_PATH still can't be overridden) Message-ID: In-Reply-To: References: <200102070137.f171bV024471@gondor.apana.org.au> X-Debian-PR-Message: closed 85123 Your message dated Sat, 10 Feb 2001 15:07:38 -0500 with message-id and subject line Bug#85123: fixed in sudo 1.6.3p5-2 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what I am talking about this indicates a serious mail system misconfiguration somewhere. Please contact me immediately.) Darren Benham (administrator, Debian Bugs database) -------------------------------------- Received: (at submit) by bugs.debian.org; 7 Feb 2001 01:37:39 +0000 From herbert@gondor.apana.org.au Tue Feb 06 19:37:39 2001 Return-path: Received: from gondor.apana.org.au [::ffff:203.14.152.114] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14QJY9-0006RK-00; Tue, 06 Feb 2001 19:37:38 -0600 Received: (from herbert@localhost) by gondor.apana.org.au (8.11.1/8.11.1/Debian 8.11.0-6) id f171bV024471; Wed, 7 Feb 2001 12:37:31 +1100 Date: Wed, 7 Feb 2001 12:37:31 +1100 Message-Id: <200102070137.f171bV024471@gondor.apana.org.au> From: Subject: sudo: SECURE_PATH still can't be overridden To: submit@bugs.debian.org X-Mailer: bug 3.3.7 Delivered-To: submit@bugs.debian.org Package: sudo Version: 1.6.3p5-1 Severity: normal It seems that Bug#20996 is still present in this version of sudo. The changelog says that it can be overridden at runtime but I haven't yet discovered how. -- System Information Debian Release: testing/unstable Kernel Version: Linux gondor 2.2.17 #1 Mon Sep 11 22:22:16 EST 2000 i586 unknown Versions of the packages sudo depends on: ii libc6 2.2.1-1 GNU C Library: Shared libraries and Timezone ii libpam-modules 0.72-12 Pluggable Authentication Modules for PAM ii libpam0g 0.72-12 Pluggable Authentication Modules library --------------------------------------- Received: (at 85123-close) by bugs.debian.org; 10 Feb 2001 20:08:08 +0000 From troup@auric.debian.org Sat Feb 10 14:08:07 2001 Return-path: Received: from auric.debian.org [::ffff:206.246.226.45] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14RgJT-0007cW-00; Sat, 10 Feb 2001 14:08:07 -0600 Received: from troup by auric.debian.org with local (Exim 3.12 1 (Debian)) id 14RgJ0-0001M4-00; Sat, 10 Feb 2001 15:07:38 -0500 From: Bdale Garbee To: 85123-close@bugs.debian.org Subject: Bug#85123: fixed in sudo 1.6.3p5-2 Message-Id: Sender: James Troup Date: Sat, 10 Feb 2001 15:07:38 -0500 Delivered-To: 85123-close@bugs.debian.org We believe that the bug you reported is fixed in the latest version of sudo, which has been installed in the Debian FTP archive: sudo_1.6.3p5-2_i386.deb to pool/main/s/sudo/sudo_1.6.3p5-2_i386.deb sudo_1.6.3p5-2.diff.gz to pool/main/s/sudo/sudo_1.6.3p5-2.diff.gz sudo_1.6.3p5-2.dsc to pool/main/s/sudo/sudo_1.6.3p5-2.dsc A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 85123@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Bdale Garbee (supplier of updated sudo package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@debian.org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sat, 10 Feb 2001 02:05:17 -0700 Source: sudo Binary: sudo Architecture: source i386 Version: 1.6.3p5-2 Distribution: unstable Urgency: low Maintainer: Bdale Garbee Changed-By: Bdale Garbee Description: sudo - Provides limited super user privileges to specific users. Closes: 70847 85123 Changes: sudo (1.6.3p5-2) unstable; urgency=low . * lose the dh_suidregister call since it's obsolete * stop using the --with-secure-path option at build time, and instead show how to set it in sudoers. Closes: #85123 * freshen config.sub and config.guess for ia64 and hppa * update sudoers man page to indicate exempt_group is on by default, closes: #70847 Files: 5e1a9fc31ad43826a41756fc698318e4 599 admin optional sudo_1.6.3p5-2.dsc 13a24d8976768863af82574795959827 24866 admin optional sudo_1.6.3p5-2.diff.gz 8b4eceed566055a37aa6e32702029cb2 123558 admin optional sudo_1.6.3p5-2_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQE6hQf+ZKfAp/LPAagRAt+HAJ9muwkJgAsy3VaLya92FWWo+lvCUwCfRtX/ sXtIuZq2uTJsdlnH14M3qWk= =R8Pt -----END PGP SIGNATURE-----   Notification sent to <herbert@gondor.apana.org.au>:
Bug acknowledged by developer.   -t  From: owner@bugs.debian.org (Debian Bug Tracking System) To: Subject: Bug#85123 acknowledged by developer (Bug#85123: fixed in sudo 1.6.3p5-2) Message-ID: In-Reply-To: <200102070137.f171bV024471@gondor.apana.org.au> References: <200102070137.f171bV024471@gondor.apana.org.au> X-Debian-PR-Message: they-closed 85123 This is an automatic notification regarding your Bug report #85123: sudo: SECURE_PATH still can't be overridden, which was filed against the sudo package. It has been closed by one of the developers, namely Bdale Garbee . Their explanation is attached below. If this explanation is unsatisfactory and you have not received a better one in a separate message then please contact the developer directly, or email 85123@bugs.debian.org or me. Darren Benham (administrator, Debian Bugs database) Received: (at 85123-close) by bugs.debian.org; 10 Feb 2001 20:08:08 +0000 From troup@auric.debian.org Sat Feb 10 14:08:07 2001 Return-path: Received: from auric.debian.org [::ffff:206.246.226.45] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14RgJT-0007cW-00; Sat, 10 Feb 2001 14:08:07 -0600 Received: from troup by auric.debian.org with local (Exim 3.12 1 (Debian)) id 14RgJ0-0001M4-00; Sat, 10 Feb 2001 15:07:38 -0500 From: Bdale Garbee To: 85123-close@bugs.debian.org Subject: Bug#85123: fixed in sudo 1.6.3p5-2 Message-Id: Sender: James Troup Date: Sat, 10 Feb 2001 15:07:38 -0500 Delivered-To: 85123-close@bugs.debian.org We believe that the bug you reported is fixed in the latest version of sudo, which has been installed in the Debian FTP archive: sudo_1.6.3p5-2_i386.deb to pool/main/s/sudo/sudo_1.6.3p5-2_i386.deb sudo_1.6.3p5-2.diff.gz to pool/main/s/sudo/sudo_1.6.3p5-2.diff.gz sudo_1.6.3p5-2.dsc to pool/main/s/sudo/sudo_1.6.3p5-2.dsc A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 85123@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Bdale Garbee (supplier of updated sudo package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@debian.org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sat, 10 Feb 2001 02:05:17 -0700 Source: sudo Binary: sudo Architecture: source i386 Version: 1.6.3p5-2 Distribution: unstable Urgency: low Maintainer: Bdale Garbee Changed-By: Bdale Garbee Description: sudo - Provides limited super user privileges to specific users. Closes: 70847 85123 Changes: sudo (1.6.3p5-2) unstable; urgency=low . * lose the dh_suidregister call since it's obsolete * stop using the --with-secure-path option at build time, and instead show how to set it in sudoers. Closes: #85123 * freshen config.sub and config.guess for ia64 and hppa * update sudoers man page to indicate exempt_group is on by default, closes: #70847 Files: 5e1a9fc31ad43826a41756fc698318e4 599 admin optional sudo_1.6.3p5-2.dsc 13a24d8976768863af82574795959827 24866 admin optional sudo_1.6.3p5-2.diff.gz 8b4eceed566055a37aa6e32702029cb2 123558 admin optional sudo_1.6.3p5-2_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQE6hQf+ZKfAp/LPAagRAt+HAJ9muwkJgAsy3VaLya92FWWo+lvCUwCfRtX/ sXtIuZq2uTJsdlnH14M3qWk= =R8Pt -----END PGP SIGNATURE-----   Received: (at 85123-close) by bugs.debian.org; 10 Feb 2001 20:08:08 +0000 From troup@auric.debian.org Sat Feb 10 14:08:07 2001 Return-path: Received: from auric.debian.org [::ffff:206.246.226.45] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14RgJT-0007cW-00; Sat, 10 Feb 2001 14:08:07 -0600 Received: from troup by auric.debian.org with local (Exim 3.12 1 (Debian)) id 14RgJ0-0001M4-00; Sat, 10 Feb 2001 15:07:38 -0500 From: Bdale Garbee To: 85123-close@bugs.debian.org Subject: Bug#85123: fixed in sudo 1.6.3p5-2 Message-Id: Sender: James Troup Date: Sat, 10 Feb 2001 15:07:38 -0500 Delivered-To: 85123-close@bugs.debian.org We believe that the bug you reported is fixed in the latest version of sudo, which has been installed in the Debian FTP archive: sudo_1.6.3p5-2_i386.deb to pool/main/s/sudo/sudo_1.6.3p5-2_i386.deb sudo_1.6.3p5-2.diff.gz to pool/main/s/sudo/sudo_1.6.3p5-2.diff.gz sudo_1.6.3p5-2.dsc to pool/main/s/sudo/sudo_1.6.3p5-2.dsc A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 85123@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Bdale Garbee (supplier of updated sudo package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@debian.org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sat, 10 Feb 2001 02:05:17 -0700 Source: sudo Binary: sudo Architecture: source i386 Version: 1.6.3p5-2 Distribution: unstable Urgency: low Maintainer: Bdale Garbee Changed-By: Bdale Garbee Description: sudo - Provides limited super user privileges to specific users. Closes: 70847 85123 Changes: sudo (1.6.3p5-2) unstable; urgency=low . * lose the dh_suidregister call since it's obsolete * stop using the --with-secure-path option at build time, and instead show how to set it in sudoers. Closes: #85123 * freshen config.sub and config.guess for ia64 and hppa * update sudoers man page to indicate exempt_group is on by default, closes: #70847 Files: 5e1a9fc31ad43826a41756fc698318e4 599 admin optional sudo_1.6.3p5-2.dsc 13a24d8976768863af82574795959827 24866 admin optional sudo_1.6.3p5-2.diff.gz 8b4eceed566055a37aa6e32702029cb2 123558 admin optional sudo_1.6.3p5-2_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQE6hQf+ZKfAp/LPAagRAt+HAJ9muwkJgAsy3VaLya92FWWo+lvCUwCfRtX/ sXtIuZq2uTJsdlnH14M3qWk= =R8Pt -----END PGP SIGNATURE-----   Information forwarded to debian-bugs-dist@lists.debian.org, Bdale Garbee <bdale@gag.com>:
Bug#85123; Package sudo.   debian-bugs-dist@lists.debian.orgBdale Garbee  Subject: Bug#85123: can you help a brother out? Reply-To: Seth Arnold , 85123@bugs.debian.org Resent-From: Seth Arnold Orignal-Sender: Seth Arnold Resent-To: debian-bugs-dist@lists.debian.org Resent-CC: Bdale Garbee Resent-Date: Wed, 14 Feb 2001 19:48:02 GMT Resent-Message-ID: Resent-Sender: owner@bugs.debian.org X-Debian-PR-Message: report 85123 X-Debian-PR-Package: sudo X-Debian-PR-Keywords: X-Loop: owner@bugs.debian.org Received: via spool by 85123-bugs@bugs.debian.org id=B85123.98217965614244 (code B ref 85123); Wed, 14 Feb 2001 19:48:02 GMT Date: Wed, 14 Feb 2001 11:41:06 -0800 From: Seth Arnold To: 85123@bugs.debian.org, herbert@gondor.apana.org.au Message-ID: <20010214114106.A20368@willamette.edu> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.3.12i Sender: Seth Arnold Delivered-To: 85123@bugs.debian.org Herbert, have you figured out the options required to make sudo revert to its old behavior of not molesting the PATH environment variable? I was rather surprised when ``sudo apt-get upgrade'' was telling me that programs I obviously have installed are not in my PATH. Thanks. -- Earthlink: The #1 provider of unsolicited bulk email to the Internet.   Acknowledgement sent to Seth Arnold <sarnold@willamette.edu>:
Extra info received and forwarded to list. Copy sent to Bdale Garbee <bdale@gag.com>.   -t  From: owner@bugs.debian.org (Debian Bug Tracking System) To: Seth Arnold Subject: Bug#85123: Info received (was can you help a brother out?) Message-ID: In-Reply-To: <20010214114106.A20368@willamette.edu> References: <20010214114106.A20368@willamette.edu> X-Debian-PR-Message: ack-info-maintonly 85123 Thank you for the additional information you have supplied regarding this problem report. It has been forwarded to the developer(s) and to the developers mailing list to accompany the original report. Your message has been sent to the package maintainer(s): Bdale Garbee If you wish to continue to submit further information on your problem, please send it to 85123@bugs.debian.org, as before. Please do not reply to the address at the top of this message, unless you wish to report a problem with the Bug-tracking system. Darren Benham (administrator, Debian Bugs database)   Received: (at 85123) by bugs.debian.org; 14 Feb 2001 19:40:56 +0000 From sarnold@home.com Wed Feb 14 13:40:56 2001 Return-path: Received: from c617208-a.salem1.or.home.com (amidala) [::ffff:24.20.70.203] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14T7nM-0003hb-00; Wed, 14 Feb 2001 13:40:56 -0600 Received: from sarnold by amidala with local (Exim 3.22 #1 (Debian)) id 14T7nW-0005J8-00; Wed, 14 Feb 2001 11:41:06 -0800 Date: Wed, 14 Feb 2001 11:41:06 -0800 From: Seth Arnold To: 85123@bugs.debian.org, herbert@gondor.apana.org.au Subject: can you help a brother out? Message-ID: <20010214114106.A20368@willamette.edu> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.3.12i Sender: Seth Arnold Delivered-To: 85123@bugs.debian.org Herbert, have you figured out the options required to make sudo revert to its old behavior of not molesting the PATH environment variable? I was rather surprised when ``sudo apt-get upgrade'' was telling me that programs I obviously have installed are not in my PATH. Thanks. -- Earthlink: The #1 provider of unsolicited bulk email to the Internet.   Information forwarded to debian-bugs-dist@lists.debian.org:
Bug#85123; Package sudo.   debian-bugs-dist@lists.debian.org  Subject: Bug#85123: can you help a brother out? Reply-To: Bdale Garbee , 85123@bugs.debian.org Resent-From: Bdale Garbee Orignal-Sender: bdale@rover.gag.com Resent-To: debian-bugs-dist@lists.debian.org Resent-Date: Wed, 14 Feb 2001 23:05:43 GMT Resent-Message-ID: Resent-Sender: owner@bugs.debian.org X-Debian-PR-Message: report 85123 X-Debian-PR-Package: sudo X-Debian-PR-Keywords: X-Loop: owner@bugs.debian.org Received: via spool by 85123-bugs@bugs.debian.org id=B85123.9821882728650 (code B ref 85123); Wed, 14 Feb 2001 23:05:43 GMT Sender: bdale@rover.gag.com To: Seth Arnold , 85123@bugs.debian.org References: <20010214114106.A20368@willamette.edu> From: Bdale Garbee Date: 14 Feb 2001 15:04:29 -0700 In-Reply-To: sarnold@willamette.edu's message of "14 Feb 2001 12:48:07 -0700" Message-ID: <87zofo3or6.fsf@rover.gag.com> Lines: 12 User-Agent: Gnus/5.0807 (Gnus v5.8.7) XEmacs/21.1 (Crater Lake) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Delivered-To: 85123@bugs.debian.org sarnold@willamette.edu (Seth Arnold) writes: > Herbert, have you figured out the options required to make sudo revert > to its old behavior of not molesting the PATH environment variable? I > was rather surprised when ``sudo apt-get upgrade'' was telling me that > programs I obviously have installed are not in my PATH. Use of the secure_path option in the sudoers file turns out to not be entirely equivalent to the definition of a secure path at compile time. I've pushed that upstream as a bug, waiting for a response. Bdale   Acknowledgement sent to Bdale Garbee <bdale@gag.com>:
Extra info received and forwarded to list.   -t  From: owner@bugs.debian.org (Debian Bug Tracking System) To: Bdale Garbee Subject: Bug#85123: Info received (was Bug#85123: can you help a brother out?) Message-ID: In-Reply-To: <87zofo3or6.fsf@rover.gag.com> References: <87zofo3or6.fsf@rover.gag.com> X-Debian-PR-Message: ack-info-maintonly 85123 Thank you for the additional information you have supplied regarding this problem report. It has been forwarded to the developer(s) and to the developers mailing list to accompany the original report. If you wish to continue to submit further information on your problem, please send it to 85123@bugs.debian.org, as before. Please do not reply to the address at the top of this message, unless you wish to report a problem with the Bug-tracking system. Darren Benham (administrator, Debian Bugs database)   Received: (at 85123) by bugs.debian.org; 14 Feb 2001 22:04:32 +0000 From bdale@gag.com Wed Feb 14 16:04:31 2001 Return-path: Received: from winfree.gag.com [::ffff:192.133.104.8] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14TA2J-0002FS-00; Wed, 14 Feb 2001 16:04:31 -0600 Received: from rover.gag.com (rover.gag.com [192.133.104.32]) by winfree.gag.com (Postfix) with ESMTP id 8A35B25AA0; Wed, 14 Feb 2001 15:04:30 -0700 (MST) Received: by rover.gag.com (Postfix, from userid 1000) id AE70E35DD5; Wed, 14 Feb 2001 15:04:29 -0700 (MST) Sender: bdale@rover.gag.com To: Seth Arnold , 85123@bugs.debian.org Subject: Re: Bug#85123: can you help a brother out? References: <20010214114106.A20368@willamette.edu> From: Bdale Garbee Date: 14 Feb 2001 15:04:29 -0700 In-Reply-To: sarnold@willamette.edu's message of "14 Feb 2001 12:48:07 -0700" Message-ID: <87zofo3or6.fsf@rover.gag.com> Lines: 12 User-Agent: Gnus/5.0807 (Gnus v5.8.7) XEmacs/21.1 (Crater Lake) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Delivered-To: 85123@bugs.debian.org sarnold@willamette.edu (Seth Arnold) writes: > Herbert, have you figured out the options required to make sudo revert > to its old behavior of not molesting the PATH environment variable? I > was rather surprised when ``sudo apt-get upgrade'' was telling me that > programs I obviously have installed are not in my PATH. Use of the secure_path option in the sudoers file turns out to not be entirely equivalent to the definition of a secure path at compile time. I've pushed that upstream as a bug, waiting for a response. Bdale   Information forwarded to debian-bugs-dist@lists.debian.org, Bdale Garbee <bdale@gag.com>:
Bug#85123; Package sudo.   debian-bugs-dist@lists.debian.orgBdale Garbee  Subject: Bug#85123: can you help a brother out? Reply-To: Seth Arnold , 85123@bugs.debian.org Resent-From: Seth Arnold Orignal-Sender: Seth Arnold Resent-To: debian-bugs-dist@lists.debian.org Resent-CC: Bdale Garbee Resent-Date: Thu, 15 Feb 2001 19:35:27 GMT Resent-Message-ID: Resent-Sender: owner@bugs.debian.org X-Debian-PR-Message: report 85123 X-Debian-PR-Package: sudo X-Debian-PR-Keywords: X-Loop: owner@bugs.debian.org Received: via spool by 85123-bugs@bugs.debian.org id=B85123.9822651465651 (code B ref 85123); Thu, 15 Feb 2001 19:35:27 GMT Date: Thu, 15 Feb 2001 11:25:57 -0800 From: Seth Arnold To: 85123@bugs.debian.org Message-ID: <20010215112557.A26086@willamette.edu> References: <20010214114106.A20368@willamette.edu> <87zofo3or6.fsf@rover.gag.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.3.15i In-Reply-To: <87zofo3or6.fsf@rover.gag.com>; from bdale@gag.com on Wed, Feb 14, 2001 at 03:04:29PM -0700 Sender: Seth Arnold Delivered-To: 85123@bugs.debian.org * Bdale Garbee [010214 14:06]: > Use of the secure_path option in the sudoers file turns out to not be entirely > equivalent to the definition of a secure path at compile time. I've pushed > that upstream as a bug, waiting for a response. :~( I am so used to software not breaking, I often forget I am running Debian *unstable*. :) Until they respond, is the correct work-around to use 'su'? Thanks. :) -- Earthlink: The #1 provider of unsolicited bulk email to the Internet.   Acknowledgement sent to Seth Arnold <sarnold@willamette.edu>:
Extra info received and forwarded to list. Copy sent to Bdale Garbee <bdale@gag.com>.   -t  From: owner@bugs.debian.org (Debian Bug Tracking System) To: Seth Arnold Subject: Bug#85123: Info received (was Bug#85123: can you help a brother out?) Message-ID: In-Reply-To: <20010215112557.A26086@willamette.edu> References: <20010215112557.A26086@willamette.edu> X-Debian-PR-Message: ack-info-maintonly 85123 Thank you for the additional information you have supplied regarding this problem report. It has been forwarded to the developer(s) and to the developers mailing list to accompany the original report. Your message has been sent to the package maintainer(s): Bdale Garbee If you wish to continue to submit further information on your problem, please send it to 85123@bugs.debian.org, as before. Please do not reply to the address at the top of this message, unless you wish to report a problem with the Bug-tracking system. Darren Benham (administrator, Debian Bugs database)   Received: (at 85123) by bugs.debian.org; 15 Feb 2001 19:25:46 +0000 From sarnold@home.com Thu Feb 15 13:25:46 2001 Return-path: Received: from c617208-a.salem1.or.home.com (amidala) [::ffff:24.20.70.203] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14TU2D-0001Sy-00; Thu, 15 Feb 2001 13:25:45 -0600 Received: from sarnold by amidala with local (Exim 3.22 #1 (Debian)) id 14TU2P-0006mr-00 for <85123@bugs.debian.org>; Thu, 15 Feb 2001 11:25:57 -0800 Date: Thu, 15 Feb 2001 11:25:57 -0800 From: Seth Arnold To: 85123@bugs.debian.org Subject: Re: Bug#85123: can you help a brother out? Message-ID: <20010215112557.A26086@willamette.edu> References: <20010214114106.A20368@willamette.edu> <87zofo3or6.fsf@rover.gag.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.3.15i In-Reply-To: <87zofo3or6.fsf@rover.gag.com>; from bdale@gag.com on Wed, Feb 14, 2001 at 03:04:29PM -0700 Sender: Seth Arnold Delivered-To: 85123@bugs.debian.org * Bdale Garbee [010214 14:06]: > Use of the secure_path option in the sudoers file turns out to not be entirely > equivalent to the definition of a secure path at compile time. I've pushed > that upstream as a bug, waiting for a response. :~( I am so used to software not breaking, I often forget I am running Debian *unstable*. :) Until they respond, is the correct work-around to use 'su'? Thanks. :) -- Earthlink: The #1 provider of unsolicited bulk email to the Internet.   Bug reopened, originator not changed. Request was from bdale@gag.com (Bdale Garbee) to control@bugs.debian.org.   Received: (at control) by bugs.debian.org; 26 Feb 2001 18:15:04 +0000 From bdale@gag.com Mon Feb 26 12:15:04 2001 Return-path: Received: from winfree.gag.com [::ffff:192.133.104.8] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14XSAq-0006Bd-00; Mon, 26 Feb 2001 12:15:04 -0600 Received: from rover.gag.com (rover.gag.com [192.133.104.32]) by winfree.gag.com (Postfix) with ESMTP id 8A5DD2588B for ; Mon, 26 Feb 2001 11:15:03 -0700 (MST) Received: by rover.gag.com (Postfix, from userid 1000) id 134D635ACA; Mon, 26 Feb 2001 11:15:02 -0700 (MST) To: control@bugs.debian.org Message-Id: <20010226181502.134D635ACA@rover.gag.com> Date: Mon, 26 Feb 2001 11:15:02 -0700 (MST) From: bdale@gag.com (Bdale Garbee) Delivered-To: control@bugs.debian.org reopen 85123 forwarded 85123 Todd.Miller@courtesan.com   Noted your statement that Bug has been forwarded to Todd.Miller@courtesan.com. Request was from bdale@gag.com (Bdale Garbee) to control@bugs.debian.org.   Received: (at control) by bugs.debian.org; 26 Feb 2001 18:15:04 +0000 From bdale@gag.com Mon Feb 26 12:15:04 2001 Return-path: Received: from winfree.gag.com [::ffff:192.133.104.8] by master.debian.org with esmtp (Exim 3.12 1 (Debian)) id 14XSAq-0006Bd-00; Mon, 26 Feb 2001 12:15:04 -0600 Received: from rover.gag.com (rover.gag.com [192.133.104.32]) by winfree.gag.com (Postfix) with ESMTP id 8A5DD2588B for ; Mon, 26 Feb 2001 11:15:03 -0700 (MST) Received: by rover.gag.com (Postfix, from userid 1000) id 134D635ACA; Mon, 26 Feb 2001 11:15:02 -0700 (MST) To: control@bugs.debian.org Message-Id: <20010226181502.134D635ACA@rover.gag.com> Date: Mon, 26 Feb 2001 11:15:02 -0700 (MST) From: bdale@gag.com (Bdale Garbee) Delivered-To: control@bugs.debian.org reopen 85123 forwarded 85123 Todd.Miller@courtesan.com   Information forwarded to debian-bugs-dist@lists.debian.org, Bdale Garbee <bdale@gag.com>:
Bug#85123; Package sudo.   debian-bugs-dist@lists.debian.orgBdale Garbee  X-Loop: owner@bugs.debian.org Subject: Bug#85123: Dear Account User, Reply-To: spamcare_desk@live.com, 85123@bugs.debian.org Resent-From: "::::Important Notice::::" Resent-To: debian-bugs-dist@lists.debian.org Resent-CC: Bdale Garbee Resent-Date: Fri, 18 Jul 2008 12:45:03 +0000 Resent-Message-ID: Resent-Sender: owner@bugs.debian.org X-Debian-PR-Message: followup 85123 X-Debian-PR-Package: sudo X-Debian-PR-Keywords: X-Debian-PR-Source: sudo Received: via spool by 85123-submit@bugs.debian.org id=B85123.121638502822326 (code B ref 85123); Fri, 18 Jul 2008 12:45:03 +0000 Received: (at 85123) by bugs.debian.org; 18 Jul 2008 12:43:48 +0000 X-Spam-Checker-Version: SpamAssassin 3.1.4-bugs.debian.org_2005_01_02 (2006-07-26) on rietz.debian.org X-Spam-Level: *** X-Spam-Status: No, score=3.2 required=4.0 tests=BAYES_50,DNS_FROM_RFC_ABUSE, DNS_FROM_RFC_POST,FROM_HAS_ULINE_NUMS autolearn=no version=3.1.4-bugs.debian.org_2005_01_02 Received: from vms044pub.verizon.net ([206.46.252.44]) by rietz.debian.org with esmtp (Exim 4.63) (envelope-from ) id 1KJpJM-0005nL-9o for 85123@bugs.debian.org; Fri, 18 Jul 2008 12:43:48 +0000 Received: from vms074.mailsrvcs.net ([172.18.12.133]) by vms044.mailsrvcs.net (Sun Java System Messaging Server 6.2-6.01 (built Apr 3 2006)) with ESMTPA id <0K47007QGCOKNTJ1@vms044.mailsrvcs.net> for 85123@bugs.debian.org; Fri, 18 Jul 2008 07:43:32 -0500 (CDT) Received: from 81.199.88.9 ([81.199.88.9]) by vms074.mailsrvcs.net (Verizon Webmail) with HTTP; Fri, 18 Jul 2008 07:43:32 -0500 (CDT) Date: Fri, 18 Jul 2008 07:43:32 -0500 (CDT) From: "::::Important Notice::::" X-Originating-IP: [81.199.88.9] To: Undisclosed recipients: ; Message-id: <33237475.2692231216385012425.JavaMail.root@vms074.mailsrvcs.net> Organization: ::::Important Notice:::: MIME-version: 1.0 Content-type: text/plain; charset=UTF-8 Content-transfer-encoding: 7bit Dear Account User, This Email is from webmail user Customer Care and we are sending it to every webmail User Accounts Owner for safety. we are having congestionsdue to the anonymous registration of accounts so we are shutting down some accounts and your account was among thoseto be deleted.We are sending you this email to you so that you can verify and let usknow if you still want to use this account.If you are still interestedplease confirm your account by fillingthe space below.Your User name,password, date of bith and your countryinformation would be needed toverify your account.Due to the congestionin all webmail users and removal of all unused Accounts, Webmail would be shutting down all unused Accounts, You will have to confirm your E-mail by filling out your Login Information below after send it to the email below, or your accountwill be suspended within 24 hours for security reasons. * Your full email id and Username: .............. * Password: ........................... * Date of Birth: ....................... * Country Or Territory: ............... Send The Above Details to our online Agent Below Email: spamcare_desk@live.com Warning!!! Account owner that refuses to update his/her account after two weeks of receiving this warning will lose his or her account permanently.Waiting to received the details of your two email. Regard, Customer Care Of Webmail   Acknowledgement sent to spamcare_desk@live.com:
Extra info received and forwarded to list. Copy sent to Bdale Garbee <bdale@gag.com>.   -t  Content-Disposition: inline Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Mailer: MIME-tools 5.420 (Entity 5.420) Content-Type: text/plain; charset=utf-8 X-Loop: owner@bugs.debian.org From: owner@bugs.debian.org (Debian Bug Tracking System) To: spamcare_desk@live.com Subject: Bug#85123: Info received (Dear Account User,) Message-ID: References: <33237475.2692231216385012425.JavaMail.root@vms074.mailsrvcs.net> X-Debian-PR-Message: ack-info 85123 X-Debian-PR-Package: sudo X-Debian-PR-Source: sudo Reply-To: 85123@bugs.debian.org Thank you for the additional information you have supplied regarding this Bug report. This is an automatically generated reply to let you know your message has been received. Your message is being forwarded to the package maintainers and other interested parties for their attention; they will reply in due course. Your message has been sent to the package maintainer(s): Bdale Garbee If you wish to submit further information on this problem, please send it to 85123@bugs.debian.org, as before. Please do not send mail to owner@bugs.debian.org unless you wish to report a problem with the Bug-tracking system. --=20 85123: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D85123 Debian Bug Tracking System Contact owner@bugs.debian.org with problems   Received: (at 85123) by bugs.debian.org; 18 Jul 2008 12:43:48 +0000 From brown_sugar3@verizon.net Fri Jul 18 12:43:48 2008 X-Spam-Checker-Version: SpamAssassin 3.1.4-bugs.debian.org_2005_01_02 (2006-07-26) on rietz.debian.org X-Spam-Level: *** X-Spam-Status: No, score=3.2 required=4.0 tests=BAYES_50,DNS_FROM_RFC_ABUSE, DNS_FROM_RFC_POST,FROM_HAS_ULINE_NUMS autolearn=no version=3.1.4-bugs.debian.org_2005_01_02 Return-path: Received: from vms044pub.verizon.net ([206.46.252.44]) by rietz.debian.org with esmtp (Exim 4.63) (envelope-from ) id 1KJpJM-0005nL-9o for 85123@bugs.debian.org; Fri, 18 Jul 2008 12:43:48 +0000 Received: from vms074.mailsrvcs.net ([172.18.12.133]) by vms044.mailsrvcs.net (Sun Java System Messaging Server 6.2-6.01 (built Apr 3 2006)) with ESMTPA id <0K47007QGCOKNTJ1@vms044.mailsrvcs.net> for 85123@bugs.debian.org; Fri, 18 Jul 2008 07:43:32 -0500 (CDT) Received: from 81.199.88.9 ([81.199.88.9]) by vms074.mailsrvcs.net (Verizon Webmail) with HTTP; Fri, 18 Jul 2008 07:43:32 -0500 (CDT) Date: Fri, 18 Jul 2008 07:43:32 -0500 (CDT) From: "::::Important Notice::::" Subject: Dear Account User, X-Originating-IP: [81.199.88.9] To: Undisclosed recipients: ; Reply-to: spamcare_desk@live.com Message-id: <33237475.2692231216385012425.JavaMail.root@vms074.mailsrvcs.net> Organization: ::::Important Notice:::: MIME-version: 1.0 Content-type: text/plain; charset=UTF-8 Content-transfer-encoding: 7bit Dear Account User, This Email is from webmail user Customer Care and we are sending it to every webmail User Accounts Owner for safety. we are having congestionsdue to the anonymous registration of accounts so we are shutting down some accounts and your account was among thoseto be deleted.We are sending you this email to you so that you can verify and let usknow if you still want to use this account.If you are still interestedplease confirm your account by fillingthe space below.Your User name,password, date of bith and your countryinformation would be needed toverify your account.Due to the congestionin all webmail users and removal of all unused Accounts, Webmail would be shutting down all unused Accounts, You will have to confirm your E-mail by filling out your Login Information below after send it to the email below, or your accountwill be suspended within 24 hours for security reasons. * Your full email id and Username: .............. * Password: ........................... * Date of Birth: ....................... * Country Or Territory: ............... Send The Above Details to our online Agent Below Email: spamcare_desk@live.com Warning!!! Account owner that refuses to update his/her account after two weeks of receiving this warning will lose his or her account permanently.Waiting to received the details of your two email. Regard, Customer Care Of Webmail