Package name
shadow-utils
Date
2004-11-04
Advisory ID
MDKSA-2004:126
Affected versions
9.2 amd64 , CS2.1 x86_64 , 10.0 amd64 , 10.1 i586 , 10.0 i586 , 9.2 i586 , MNF8.2 i586 , CS2.1 i586 , 10.1 x86_64

Problem description

A vulnerability in the shadow suite was discovered by Martin Schulze that can be exploited by local users to bypass certain security restrictions due to an input validation error in the passwd_check() function. This function is used by the chfn and chsh tools. The updated packages have been patched to prevent this problem.

Updated packages

9.2 amd64

 cb2c6e2a866acd66b199d26c931156ed  amd64/9.2/RPMS/shadow-utils-4.0.3-5.1.92mdk.amd64.rpm
002303dab59ab225b54c7326e65fd6e2  amd64/9.2/SRPMS/shadow-utils-4.0.3-5.1.92mdk.src.rpm

CS2.1 x86_64

 793499a2e451a4e094071ec99b5e938c  x86_64/corporate/2.1/RPMS/shadow-utils-20000902-10.1.C21mdk.x86_64.rpm
fda9c8a42041a45fce3b89ac7c5fa4bc  x86_64/corporate/2.1/SRPMS/shadow-utils-20000902-10.1.C21mdk.src.rpm

10.0 amd64

 ab7dd6ff065b58c3566cb7b22d3621f9  amd64/10.0/RPMS/shadow-utils-4.0.3-8.1.100mdk.amd64.rpm
b614188ebd45398b9211c623703e192f  amd64/10.0/SRPMS/shadow-utils-4.0.3-8.1.100mdk.src.rpm

10.1 i586

 f4eb58ab0b8da58a33ce2c0cf4c7d87f  10.1/RPMS/shadow-utils-4.0.3-8.1.101mdk.i586.rpm
89fe1fc7fe11812bd4a1ae913334d7f6  10.1/SRPMS/shadow-utils-4.0.3-8.1.101mdk.src.rpm

10.0 i586

 0ba43408dbd43f4cb91f0409c55d2a33  10.0/RPMS/shadow-utils-4.0.3-8.1.100mdk.i586.rpm
b614188ebd45398b9211c623703e192f  10.0/SRPMS/shadow-utils-4.0.3-8.1.100mdk.src.rpm

9.2 i586

 24cf182746a19950907d229076a36a50  9.2/RPMS/shadow-utils-4.0.3-5.1.92mdk.i586.rpm
002303dab59ab225b54c7326e65fd6e2  9.2/SRPMS/shadow-utils-4.0.3-5.1.92mdk.src.rpm

MNF8.2 i586

 b37dbc5eeb09399f5227559779b1c7d9  mnf8.2/RPMS/shadow-utils-20000902-5.2.M82mdk.i586.rpm
bbe070cc85b48a9f79234aded8d14d3f  mnf8.2/SRPMS/shadow-utils-20000902-5.2.M82mdk.src.rpm

CS2.1 i586

 6af1c44ec3708155e84453f24d02ecaf  corporate/2.1/RPMS/shadow-utils-20000902-10.1.C21mdk.i586.rpm
fda9c8a42041a45fce3b89ac7c5fa4bc  corporate/2.1/SRPMS/shadow-utils-20000902-10.1.C21mdk.src.rpm

10.1 x86_64

 e99e42d23e61c94beeeaf4a34c87bf03  x86_64/10.1/RPMS/shadow-utils-4.0.3-8.1.101mdk.x86_64.rpm
89fe1fc7fe11812bd4a1ae913334d7f6  x86_64/10.1/SRPMS/shadow-utils-4.0.3-8.1.101mdk.src.rpm

References