New Debian shadow 1:4.5-1.1+deb10u1 fixes: This update addresses the following issues: 1:4.5-1.1+deb10u1 (Sat, 26 Oct 2024 15:24:09 +0300) * Non-maintainer upload by the ELTS Team. * CVE-2018-7169: unprivileged user can drop supplementary groups * CVE-2023-4641: gpasswd password leak * CVE-2023-29383: chfn missing control character check
--- mirror/ftp/pool/main/s/shadow/shadow_4.5-1.1.dsc +++ apt/ucs_5.0-0-errata5.0-9/source/shadow_4.5-1.1+deb10u1.dsc @@ -1,3 +1,10 @@ +1:4.5-1.1+deb10u1 [Sat, 26 Oct 2024 15:24:09 +0300] Adrian Bunk <bunk@debian.org>: + + * Non-maintainer upload by the ELTS Team. + * CVE-2018-7169: unprivileged user can drop supplementary groups + * CVE-2023-4641: gpasswd password leak + * CVE-2023-29383: chfn missing control character check + 1:4.5-1.1 [Fri, 27 Jul 2018 10:07:37 +0200] Andreas Henriksson <andreas@fatal.se>: * Non-maintainer upload (greetings from DebCamp/DebConf Taiwan). <http://piuparts.knut.univention.de/5.0-9/#6075334374242995627>
OK: bug OK: yaml OK: announce_errata OK: patch ~OK: piuparts Freexian ships dbgsym packages [5.0-9] 778902edce Bug #57720: shadow 1:4.5-1.1+deb10u1 doc/errata/staging/shadow.yaml | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x1158>