USN-5745-1: shadow vulnerability
28 November 2022
shadow could be made to overwrite files.
Releases
Packages
- shadow - system login tools
Details
Florian Weimer discovered that shadow was not properly copying and removing
user directory trees, which could lead to a race condition. A local attacker
could possibly use this issue to setup a symlink attack and alter or remove
directories without authorization.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.10
-
passwd
-
1:4.11.1+dfsg1-2ubuntu1.1
-
login
-
1:4.11.1+dfsg1-2ubuntu1.1
-
libsubid4
-
1:4.11.1+dfsg1-2ubuntu1.1
-
uidmap
-
1:4.11.1+dfsg1-2ubuntu1.1
Ubuntu 22.04
Ubuntu 20.04
-
passwd
-
1:4.8.1-1ubuntu5.20.04.3
-
login
-
1:4.8.1-1ubuntu5.20.04.3
-
uidmap
-
1:4.8.1-1ubuntu5.20.04.3
Ubuntu 18.04
Ubuntu 16.04
-
passwd
-
1:4.2-3.1ubuntu5.5+esm2
Available with Ubuntu Pro
-
login
-
1:4.2-3.1ubuntu5.5+esm2
Available with Ubuntu Pro
-
uidmap
-
1:4.2-3.1ubuntu5.5+esm2
Available with Ubuntu Pro
Ubuntu 14.04
-
passwd
-
1:4.1.5.1-1ubuntu9.5+esm2
Available with Ubuntu Pro
-
login
-
1:4.1.5.1-1ubuntu9.5+esm2
Available with Ubuntu Pro
-
uidmap
-
1:4.1.5.1-1ubuntu9.5+esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.