https://seclists.org/oss-sec/2025/q2/200: Local information disclosuin apport and systemd-codump
Published Jun 3, 2025
·Updated
Affected Software
1 affected component
Shadow shadow
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
The severity of CVE-2025-XXXX is categorized as medium due to the potential for local information disclosure.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, upgrade to the latest version of the Shadow package that addresses the coredump handling.
3
Who is affected by CVE-2025-XXXX?
Users of the Shadow package who encounter frequent coredumps of unix_chkpwd are affected by CVE-2025-XXXX.
4
What is the nature of the vulnerability in CVE-2025-XXXX?
CVE-2025-XXXX involves local information disclosure due to coredumps potentially revealing sensitive data.
5
When was CVE-2025-XXXX published?
CVE-2025-XXXX was published on June 3, 2025.