RHSA-2024:2577: Low: shadow-utils security update
Low: shadow-utils security update
Other sources
The shadow-utils packages include programs for converting UNIX password files tothe shadow password format, as well as utilities for managing user and groupaccounts.Security Fix(es): shadow-utils: possible password leak during passwd(1) change (CVE-2023-4641) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/shadow-utilsto a version that resolves this vulnerability.Fixed in 4.6-17.el8_8.2 - Upgrade
Upgrade
redhat/shadow-utils-debuginfoto a version that resolves this vulnerability.Fixed in 4.6-17.el8_8.2 - Upgrade
Upgrade
redhat/shadow-utils-debugsourceto a version that resolves this vulnerability.Fixed in 4.6-17.el8_8.2 - Upgrade
Upgrade
redhat/shadow-utils-subidto a version that resolves this vulnerability.Fixed in 4.6-17.el8_8.2 - Upgrade
Upgrade
redhat/shadow-utils-subid-debuginfoto a version that resolves this vulnerability.Fixed in 4.6-17.el8_8.2 - Upgrade
Upgrade
redhat/shadow-utilsto a version that resolves this vulnerability.Fixed in 4.6-17.el8_8.2.aa - Upgrade
Upgrade
redhat/shadow-utils-debuginfoto a version that resolves this vulnerability.Fixed in 4.6-17.el8_8.2.aa - Upgrade
Upgrade
redhat/shadow-utils-debugsourceto a version that resolves this vulnerability.Fixed in 4.6-17.el8_8.2.aa - Upgrade
Upgrade
redhat/shadow-utils-subidto a version that resolves this vulnerability.Fixed in 4.6-17.el8_8.2.aa - Upgrade
Upgrade
redhat/shadow-utils-subid-debuginfoto a version that resolves this vulnerability.Fixed in 4.6-17.el8_8.2.aa - Upgrade
Upgrade
redhat/shadow-utils-subid-develto a version that resolves this vulnerability.Fixed in 4.6-17.el8_8.2 - Upgrade
Upgrade
redhat/shadow-utils-subid-develto a version that resolves this vulnerability.Fixed in 4.6-17.el8_8.2.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2577?
The severity of RHSA-2024:2577 is classified as low.
How do I fix RHSA-2024:2577?
To fix RHSA-2024:2577, update the shadow-utils package to version 4.6-17.el8_8.2.
What vulnerabilities are addressed in RHSA-2024:2577?
RHSA-2024:2577 addresses a possible password leak during password handling.
Which Red Hat products are affected by RHSA-2024:2577?
Affected products include various versions of Red Hat Enterprise Linux and CodeReady Linux Builder.
Is there a recommended action for RHSA-2024:2577?
Yes, it is recommended to apply the security update to mitigate the vulnerability.