USN-5254-1: shadow vulnerabilities
27 January 2022
Several security issues were fixed in shadow.
Releases
Packages
- shadow - system login tools
Details
It was discovered that shadow incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
expose sensitive information. This issue only affected
Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. (CVE-2017-12424)
It was discovered that shadow incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2018-7169)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
Ubuntu 16.04
-
login
-
1:4.2-3.1ubuntu5.5+esm1
Available with Ubuntu Pro
-
passwd
-
1:4.2-3.1ubuntu5.5+esm1
Available with Ubuntu Pro
-
uidmap
-
1:4.2-3.1ubuntu5.5+esm1
Available with Ubuntu Pro
Ubuntu 14.04
-
login
-
1:4.1.5.1-1ubuntu9.5+esm1
Available with Ubuntu Pro
-
passwd
-
1:4.1.5.1-1ubuntu9.5+esm1
Available with Ubuntu Pro
-
uidmap
-
1:4.1.5.1-1ubuntu9.5+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.