CVE-2013-4235: Race Condition
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
Affected Software
Event History
Frequently Asked Questions
What is CVE-2013-4235?
CVE-2013-4235 is a vulnerability in the shadow package that allows a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
What is the severity of CVE-2013-4235?
The severity of CVE-2013-4235 is medium with a CVSS score of 4.7.
Which software is affected by CVE-2013-4235?
The shadow package in Debian, Debian Linux 8.0, Debian Linux 9.0, Debian Linux 10.0, Fedora 16, Fedora 17, Redhat Enterprise Linux 5, and Redhat Enterprise Linux 6.0 is affected by CVE-2013-4235.
How can I fix CVE-2013-4235?
To fix CVE-2013-4235, you should update the shadow package to version 1:4.13+dfsg1-1, 1:4.13+dfsg1-2, or 1:4.13+dfsg1-3.
Where can I find more information about CVE-2013-4235?
You can find more information about CVE-2013-4235 on the following references: [GitHub Issue](https://github.com/shadow-maint/shadow/issues/317), [GitHub Pull Request](https://github.com/shadow-maint/shadow/pull/545), [GitHub Commit](https://github.com/shadow-maint/shadow/commit/e9ae247cb14f977d8881f481488843b10665dba8).