Shadow-maint

Shadow-utils

2 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.6%
  • Published 26.12.2024 09:15:07
  • Last modified 26.12.2024 09:15:07

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, pote...

  • EPSS 0.02%
  • Published 27.12.2023 16:15:13
  • Last modified 21.11.2024 08:35:35

A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker w...