UbuntuUpdates.org

Package "shadow"

Name: shadow

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • system login tools
  • change and administer password and group data

Latest version: 1:4.1.4.2+svn3283-3ubuntu5.2
Release: precise (12.04)
Level: security
Repository: main

Links



Other versions of "shadow" in Precise

Repository Area Version
base main 1:4.1.4.2+svn3283-3ubuntu5
updates main 1:4.1.4.2+svn3283-3ubuntu5.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1:4.1.4.2+svn3283-3ubuntu5.2 2021-05-03 15:06:19 UTC

  shadow (1:4.1.4.2+svn3283-3ubuntu5.2) precise-security; urgency=medium

  * SECURITY UPDATE: preventing tty hijacking.
    - debian/patches/0001-Do_not_foward_controlling_terminal.patch
      No CVE is currently assigned. Upstream patch.
  [ Seth Arnold ]
  * SECURITY UPDATE: su could be used to kill arbitrary process.
    - debian/patches/CVE-2017-2616.patch: Check process's exit status before
      sending signal. This patch is a combined patch with original and
      regression patch
    - CVE-2017-2616

 -- <email address hidden> (Leonidas S. Barbosa) Thu, 22 Jun 2017 11:08:53 -0300

CVE-2017-2616 Sending SIGKILL to other processes with root privileges via su



About   -   Send Feedback to @ubuntu_updates