Security update for shadow
Announcement ID: | SUSE-SU-2024:1007-2 |
---|---|
Rating: | moderate |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves two vulnerabilities and has seven security fixes can now be installed.
Description:
This update for shadow fixes the following issues:
- CVE-2023-29383: Fixed apparent /etc/shadow manipulation via chfn (bsc#1210507).
- CVE-2023-4641: Fixed possible password leak during passwd(1) change (bsc#1214806).
The following non-security bugs were fixed:
- bsc#1176006: Fix chage date miscalculation
- bsc#1188307: Fix passwd segfault
- bsc#1203823: Remove pam_keyinit from PAM config files
- bsc#1213189: Change lock mechanism to file locking to prevent lock files after power interruptions
- bsc#1206627: Add --prefix support to passwd, chpasswd and chage
- bsc#1205502: useradd audit event user id field cannot be interpretedd
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2024-1007=1
Package List:
-
SUSE Linux Enterprise Micro 5.5 (noarch)
- login_defs-4.8.1-150500.3.3.1
-
SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
- shadow-4.8.1-150500.3.3.1
- shadow-debugsource-4.8.1-150500.3.3.1
- shadow-debuginfo-4.8.1-150500.3.3.1
References:
- https://www.suse.com/security/cve/CVE-2023-29383.html
- https://www.suse.com/security/cve/CVE-2023-4641.html
- https://bugzilla.suse.com/show_bug.cgi?id=1144060
- https://bugzilla.suse.com/show_bug.cgi?id=1176006
- https://bugzilla.suse.com/show_bug.cgi?id=1188307
- https://bugzilla.suse.com/show_bug.cgi?id=1203823
- https://bugzilla.suse.com/show_bug.cgi?id=1205502
- https://bugzilla.suse.com/show_bug.cgi?id=1206627
- https://bugzilla.suse.com/show_bug.cgi?id=1210507
- https://bugzilla.suse.com/show_bug.cgi?id=1213189
- https://bugzilla.suse.com/show_bug.cgi?id=1214806