First published: Mon Jun 19 2023(Updated: )
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/shadow | <=1:4.5-1.1<=1:4.8.1-1<=1:4.13+dfsg1-1 | 1:4.13+dfsg1-4 |
redhat/shadow-utils | <4.14.0 | 4.14.0 |
ubuntu/shadow | <1:4.5-1ubuntu2.5+ | 1:4.5-1ubuntu2.5+ |
ubuntu/shadow | <1:4.8.1-1ubuntu5.20.04.5 | 1:4.8.1-1ubuntu5.20.04.5 |
ubuntu/shadow | <1:4.8.1-2ubuntu2.2 | 1:4.8.1-2ubuntu2.2 |
ubuntu/shadow | <1:4.13+dfsg1-1ubuntu1.1 | 1:4.13+dfsg1-1ubuntu1.1 |
ubuntu/shadow | <1:4.1.5.1-1ubuntu9.5+ | 1:4.1.5.1-1ubuntu9.5+ |
ubuntu/shadow | <1:4.13+dfsg1-2<4.14.0 | 1:4.13+dfsg1-2 4.14.0 |
ubuntu/shadow | <1:4.2-3.1ubuntu5.5+ | 1:4.2-3.1ubuntu5.5+ |
Shadow-maint Shadow-utils | <4.14.0 | |
Redhat Codeready Linux Builder | =8.0 | |
Redhat Codeready Linux Builder | =9.0 | |
Redhat Codeready Linux Builder For Arm64 | =8.0_aarch64 | |
Redhat Codeready Linux Builder For Arm64 | =9.0_aarch64 | |
Redhat Codeready Linux Builder For Ibm Z Systems | =8.0_s390x | |
Redhat Codeready Linux Builder For Ibm Z Systems | =9.0_s390x | |
Redhat Codeready Linux Builder For Power Little Endian | =8.0_ppc64le | |
Redhat Codeready Linux Builder For Power Little Endian | =9.0_ppc64le | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =9.0 | |
Redhat Enterprise Linux For Arm 64 | =8.0 | |
Redhat Enterprise Linux For Arm 64 | =9.0 | |
Redhat Enterprise Linux For Ibm Z Systems | =8.0_s390x | |
Redhat Enterprise Linux For Ibm Z Systems | =9.0_s390x | |
Redhat Enterprise Linux For Power Little Endian | =8.0_ppc64le | |
Redhat Enterprise Linux For Power Little Endian | =9.0_ppc64le |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.