From 7d7e24d16780c16c7296ac5420dbe7d65f07f082 Mon Sep 17 00:00:00 2001 From: "Todd C. Miller" Date: Sat, 11 Dec 2021 16:27:58 -0700 Subject: [PATCH] Bugs #1013 and #1014 --- NEWS | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/NEWS b/NEWS index 17d864368..26b81a717 100644 --- a/NEWS +++ b/NEWS @@ -81,6 +81,13 @@ What's new in Sudo 1.9.9 may be required. The merging of sudoers rules is currently fairly simplistic but will be improved in a future release. + * Sudo was parsing but not applying the "deref" and "tls_reqcert" + ldap.conf settings. This meant the options were effectively + ignored which broke dereferencing of aliases in LDAP. Bug #1013. + + * Clarified in the sudo man page that the security policy may + override the user's PATH environment variable. Bug #1014. + What's new in Sudo 1.9.8p2 * Fixed a potential out-of-bounds read with "sudo -i" when the