UbuntuUpdates.org

Package "passwd"

Name: passwd

Description:

change and administer password and group data

Latest version: 1:4.13+dfsg1-1ubuntu1.1
Release: mantic (23.10)
Level: security
Repository: main
Head package: shadow
Homepage: https://github.com/shadow-maint/shadow

Links


Download "passwd"


Other versions of "passwd" in Mantic

Repository Area Version
base main 1:4.13+dfsg1-1ubuntu1
updates main 1:4.13+dfsg1-1ubuntu1.1

Changelog

Version: 1:4.13+dfsg1-1ubuntu1.1 2024-02-15 20:07:29 UTC

  shadow (1:4.13+dfsg1-1ubuntu1.1) mantic-security; urgency=medium

  * SECURITY UPDATE: unsanitized buffer leading to a password leak during
    gpasswd new password operation
    - debian/patches/CVE-2023-4641.patch: fix password leak in gpasswd.
    - CVE-2023-4641

 -- Camila Camargo de Matos <email address hidden> Tue, 06 Feb 2024 09:53:32 -0300

CVE-2023-4641 A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt,



About   -   Send Feedback to @ubuntu_updates