First published: Tue Dec 03 2019(Updated: )
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Debian shadow | ||
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =16 | |
Fedoraproject Fedora | =17 | |
Redhat Enterprise Linux | =5 | |
Redhat Enterprise Linux | =6.0 | |
debian/shadow | <=1:4.8.1-1 | 1:4.13+dfsg1-1 1:4.15.3-2 1:4.16.0-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4235 is a vulnerability in the shadow package that allows a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
The severity of CVE-2013-4235 is medium with a CVSS score of 4.7.
The shadow package in Debian, Debian Linux 8.0, Debian Linux 9.0, Debian Linux 10.0, Fedora 16, Fedora 17, Redhat Enterprise Linux 5, and Redhat Enterprise Linux 6.0 is affected by CVE-2013-4235.
To fix CVE-2013-4235, you should update the shadow package to version 1:4.13+dfsg1-1, 1:4.13+dfsg1-2, or 1:4.13+dfsg1-3.
You can find more information about CVE-2013-4235 on the following references: [GitHub Issue](https://github.com/shadow-maint/shadow/issues/317), [GitHub Pull Request](https://github.com/shadow-maint/shadow/pull/545), [GitHub Commit](https://github.com/shadow-maint/shadow/commit/e9ae247cb14f977d8881f481488843b10665dba8).