Download
| Alert*
oval:org.secpod.oval:def:78192
shadow: system login tools Several security issues were fixed in shadow. oval:org.secpod.oval:def:89002578 This update for shadow fixes the following issues: - CVE-2018-7169: Fixed an privilege escalation in newgidmap, which allowed an unprivileged user to be placed in a user namespace where setgroups is allowed oval:org.secpod.oval:def:1900075 An issue was discovered in login 4.5. new gidmap is setuid and allows an unprivileged user to be placed in a user namespace where setgroups is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator h ... oval:org.secpod.oval:def:2000758 An issue was discovered in shadow 4.5. newgidmap is setuid and allows an unprivileged user to be placed in a user namespace where setgroups is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator ... oval:org.secpod.oval:def:114611 The shadow-utils package includes the necessary programs for converting UNIX password files to the shadow password format, plus programs for managing user and group accounts. The pwconv command converts passwords to the shadow password format. The pwunconv command unconverts shadow passwords and gen ... oval:org.secpod.oval:def:706295 shadow: system login tools Several security issues were fixed in shadow. |