From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by finch.gentoo.org (Postfix) with ESMTPS id 19DA81396D9 for ; Sun, 15 Oct 2017 20:19:43 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 9CFF12BC081; Sun, 15 Oct 2017 20:19:00 +0000 (UTC) Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 86A392BC00C for ; Sun, 15 Oct 2017 20:18:35 +0000 (UTC) Received: from localhost.localdomain (pool-108-48-108-145.washdc.fios.verizon.net [108.48.108.145]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: bman) by smtp.gentoo.org (Postfix) with ESMTPSA id 7731C33BEC0 for ; Sun, 15 Oct 2017 20:18:34 +0000 (UTC) From: Aaron Bauman To: gentoo-announce@lists.gentoo.org Reply-To: security@gentoo.org Subject: [gentoo-announce] [ GLSA 201710-16 ] Shadow: Buffer overflow Date: Sun, 15 Oct 2017 16:18:32 -0400 Message-ID: <2657178.plCNApizkZ@localhost.localdomain> Organization: Gentoo Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-announce@lists.gentoo.org MIME-Version: 1.0 Content-Type: multipart/signed; boundary="nextPart1834968.ss5QR05oWR"; micalg="pgp-sha256"; protocol="application/pgp-signature" X-Archives-Salt: 21efe291-7b37-441b-beee-bfc06ad808ee X-Archives-Hash: e15a399a6f72206e222f6356cb17810f --nextPart1834968.ss5QR05oWR Content-Transfer-Encoding: 7Bit Content-Type: text/plain; charset="us-ascii" - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201710-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Shadow: Buffer overflow Date: October 15, 2017 Bugs: #627044 ID: 201710-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability found in Shadow may allow remote attackers to cause a Denial of Service condition or produce other unspecified behaviors. Background ========== Shadow is a set of tools to deal with user accounts. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/shadow < 4.5 >= 4.5 Description =========== Malformed input in the newusers tool may produce crashes and other unspecified behaviors. Impact ====== A remote attacker could possibly cause a Denial of Service condition or bypass privilege boundaries in some web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts. Workaround ========== There is no known workaround at this time. Resolution ========== All Shadow users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/shadow-4.5" References ========== [ 1 ] CVE-2017-12424 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12424 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201710-16 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2017 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 --nextPart1834968.ss5QR05oWR Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part. Content-Transfer-Encoding: 7Bit -----BEGIN PGP SIGNATURE----- iQEzBAABCAAdFiEEiDRK3jyVBE/RkymqpRQw84X1dt0FAlnjwpgACgkQpRQw84X1 dt3gDgf8D2c1LqRGkqPsJS1vZ3WStsxrpvvtvGOm3qEifukgig/lVqKyYMItWypj 1vaTHeUgxOv6S29+OmBADMYZ5d17PHaVljt0d0DNP7OFQ5NSayKsMhajNMv5npbp I/X7nT0FAr3eikfHH2npwBVCZq+JLujjrFrEqq2+yoyV2Rn303a0xCxgWgDskSft Ia8a2hx/mUHV2C9ZokL18hnkyJ31FVkhuYfD7718pt90W1SzQADGHNB9DSUNhN7t GsjMJ8iN7rLZXQhIoawFEqoka6JPZctygLts46861AKjH5gJIMe2no4KPUyHCA3g TVsj+ER0W9acDKl92gOfJBJae5C4TA== =3fKl -----END PGP SIGNATURE----- --nextPart1834968.ss5QR05oWR--