Solved Debian stretch security updates missing?

Status
Not open for further replies.

andy184

Joined
Feb 11, 2021
Messages
4
Reaction score
0
Hello,

Can anyone confirm how security updates are handled on 3CX Debian installs?

I see from comments elsewhere in the forums that 3CX should automatically install security updates to the OS, however, auditing our install for protection against CVE-2021-3156 (sudo privilege escalation) I noticed we are still running sudo 1.8.19p1-2.1+deb9u2 which is vulnerable.

apt-cache policy shows that it knows about the updated version but this has been pinned low priority

Code:
  $ apt-cache policy sudo
  Installed: 1.8.19p1-2.1+deb9u2
  Candidate: 1.8.19p1-2.1+deb9u2
  Version table:
     1.8.19p1-2.1+deb9u3 -1
        500 http://security.debian.org stretch/updates/main amd64 Packages
 *** 1.8.19p1-2.1+deb9u2 1000
        500 http://deb.debian.org/debian stretch/main amd64 Packages
        100 /var/lib/dpkg/status
 
Thanks for your reply, but just to be clear CVE-2021-3156 is resolved in 1.8.19p1-2.1+deb9u3 which the Debian Security team have addressed.

It is installed on every other (non-3cx) stretch Debian install we have.

See https://security-tracker.debian.org/tracker/CVE-2021-3156
stretch (security) fixed.
 
Hello,
Will this be resolved? The sudo is still vulnerable on debian 3cx installation.
Thanks,
Levi
 
Hello,
Will this be resolved? The sudo is still vulnerable on debian 3cx installation.
Thanks,
Levi
As this is a "no DSA" it is classed as a minor issue.
To answer your questions, yes, on the next iteration of the security updates it should be patched automatically, so no need to do anything (as long as you have automatic updates enabled of course...).
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet