UbuntuUpdates.org

Package "login"

Name: login

Description:

system login tools

Latest version: 1:4.8.1-2ubuntu2.2
Release: jammy (22.04)
Level: security
Repository: main
Head package: shadow
Homepage: https://github.com/shadow-maint/shadow

Links


Download "login"


Other versions of "login" in Jammy

Repository Area Version
base main 1:4.8.1-2ubuntu2
updates main 1:4.8.1-2ubuntu2.2

Changelog

Version: 1:4.8.1-2ubuntu2.2 2024-02-15 20:07:15 UTC
No changelog available yet.
Source diff to previous version

Version: 1:4.8.1-2ubuntu2.1 2022-11-28 15:07:59 UTC

  shadow (1:4.8.1-2ubuntu2.1) jammy-security; urgency=medium

  * SECURITY UPDATE: race condition when copying and removing directory trees
    - debian/patches/CVE-2013-4235-pre1.patch: add nofollow to opens.
    - debian/patches/CVE-2013-4235-pre2.patch: prepare context for actual file
      type (set_selinux_file_context).
    - debian/patches/CVE-2013-4235-1.patch: avoid races in chown_tree().
    - debian/patches/CVE-2013-4235-2.patch: avoid races in remove_tree().
    - debian/patches/CVE-2013-4235-3.patch: require symlink support.
    - debian/patches/CVE-2013-4235-4.patch: fail if regular file pre-exists in
      copy_tree().
    - debian/patches/CVE-2013-4235-5.patch: more robust file content copy in
      copy_tree().
    - debian/patches/CVE-2013-4235-6.patch: address minor compiler warnings.
    - debian/patches/CVE-2013-4235-7.patch: avoid races in copy_tree().
    - debian/patches/CVE-2013-4235-post1.patch: use fchmodat instead of chmod
      (copy_tree).
    - debian/patches/CVE-2013-4235-post2.patch: do not block on fifos
      (copy_tree).
    - debian/patches/CVE-2013-4235-post3.patch: carefully treat permissions
      (copy_tree).
    - CVE-2013-4235

 -- Camila Camargo de Matos <email address hidden> Thu, 24 Nov 2022 09:05:18 -0300

CVE-2013-4235 shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees



About   -   Send Feedback to @ubuntu_updates