New Debian shadow 1:4.13+dfsg1-1+deb12u1 fixes: This update addresses the following issues: 1:4.13+dfsg1-1+deb12u1 (Mon, 07 Apr 2025 12:38:46 +0200) [ Balint Reczey ] * Cherry-pick upstream patch to fix gpasswd passwd leak CVE-2023-4641 * Cherry-pick upstream patch to fix chfn vulnerability CVE-2023-29383 * Fix valid_field() that regressed in upstream's chfn fix [ Chris Hofstaedtler ] * Update Uploaders: field from unstable
--- mirror/ftp/pool/main/s/shadow/shadow_4.13+dfsg1-1.dsc +++ apt/ucs_5.2-0-errata5.2-1/source/shadow_4.13+dfsg1-1+deb12u1.dsc @@ -1,3 +1,15 @@ +1:4.13+dfsg1-1+deb12u1 [Mon, 07 Apr 2025 12:38:46 +0200] Chris Hofstaedtler <zeha@debian.org>: + + [ Balint Reczey ] + * Cherry-pick upstream patch to fix gpasswd passwd leak (Closes: #1051062) + CVE-2023-4641 + * Cherry-pick upstream patch to fix chfn vulnerability (Closes: #1034482) + CVE-2023-29383 + * Fix valid_field() that regressed in upstream's chfn fix + + [ Chris Hofstaedtler ] + * Update Uploaders: field from unstable + 1:4.13+dfsg1-1 [Fri, 11 Nov 2022 09:28:15 +0100] Balint Reczey <balint@balintreczey.hu>: [ Balint Reczey ] <http://piuparts.knut.univention.de/5.2-1/#1836886101066012676>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-1] ccab18ce6ff Bug #58284: shadow 1:4.13+dfsg1-1+deb12u1 doc/errata/staging/shadow.yaml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x102>