shadow-utils-4.6-19.el8
エラータID: AXSA:2023-7078:04
Release date:
Friday, December 22, 2023 - 07:17
Subject:
shadow-utils-4.6-19.el8
Affected Channels:
Asianux Server 8 for x86_64
Severity:
Low
Description:
The shadow-utils packages include programs for converting UNIX password files to the shadow password format, as well as utilities for managing user and group accounts.
Security Fix(es):
* shadow-utils: possible password leak during passwd(1) change (CVE-2023-4641)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2023-4641
RESERVED
Solution:
Update packages.
CVEs:
CVE-2023-4641
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.
Additional Info:
N/A
Download:
SRPMS
- shadow-utils-4.6-19.el8.src.rpm
MD5: d1d90950c3deada559943857c6159d72
SHA-256: 2c0339e23db31434d1d2a33c4586c7b71678beb502eac890f5ab2a75f3447fcd
Size: 1.76 MB
Asianux Server 8 for x86_64
- shadow-utils-4.6-19.el8.x86_64.rpm
MD5: f416d8e612684a9f723fed1814b86902
SHA-256: e2cbf9410ca34d1568c1efeffb4b46e65fb50ed1068fa6bd44ab5e836e968713
Size: 1.23 MB - shadow-utils-subid-4.6-19.el8.i686.rpm
MD5: 3e313610ca25b65bfdff6144d9254626
SHA-256: 18d34b0af6fc836b4aba7f6749a45616d8d1d2b71dfe122a2cb24bca05c3119d
Size: 117.62 kB - shadow-utils-subid-4.6-19.el8.x86_64.rpm
MD5: 01d041305621d2d26dd584a81a063497
SHA-256: 50d7d1c073e107133103aa497b7a82a79ea785a5df37ca97334584143e19e88f
Size: 111.85 kB - shadow-utils-subid-devel-4.6-19.el8.i686.rpm
MD5: 4d6c629b9e07c9ec4a77126a7e17ebae
SHA-256: 814108d0ed53c30f017c678d9676683210b0295e43af47ff46122dae16ade929
Size: 40.55 kB - shadow-utils-subid-devel-4.6-19.el8.x86_64.rpm
MD5: 018baa5cb1a48cbb5d7c5ff9466b855a
SHA-256: 40e5f61cb93e6cd0e2113d5e14cda45bf6299afdd6c03b335d8a30d5d245959a
Size: 40.53 kB