Skip to main content
Hello,
We have the Rocket port of sudo 1.8.6p3 that can be downloaded from Open Source Languages and Tools for z/OS and would like to know if this software also has the vulnerability described in CVE-2021-3156: NVD
Regards,
Werner
Hello,
We have the Rocket port of sudo 1.8.6p3 that can be downloaded from Open Source Languages and Tools for z/OS and would like to know if this software also has the vulnerability described in CVE-2021-3156: NVD
Regards,
Werner
Hello Werner,

So far we've been unable to recreate the issue on z/OS. Nevertheless we are working on applying the patch, and the updated build will be available on Rocket Secure server. Please note that open source tools ported by Rocket are now delivered in a different way; see this topic and this presentation for details. Sudo 1.8.6p3 is an outdated version and has been replaced with 1.8.21p2.

Thanks,
Vladimir

Hello,
We have the Rocket port of sudo 1.8.6p3 that can be downloaded from Open Source Languages and Tools for z/OS and would like to know if this software also has the vulnerability described in CVE-2021-3156: NVD
Regards,
Werner
A new release of sudo (sudo-1.8.21p2-7) is now available for download and install via conda from Rocket's secure conda channel server.

This release contains the patch to resolve the security vulnerability CVE-2021-3156.