Описание
Security update for shadow
This update for shadow fixes the following issues:
- CVE-2016-6252: Fixed incorrect integer handling that could results in a local privilege escalation (bsc#1099310)
Список пакетов
SUSE Linux Enterprise Server 12 SP1-LTSS
shadow-4.1.5.1-19.8.1
SUSE Linux Enterprise Server 12-LTSS
shadow-4.1.5.1-19.8.1
SUSE Linux Enterprise Server for SAP Applications 12 SP1
shadow-4.1.5.1-19.8.1
Ссылки
- Link for SUSE-SU-2018:1995-1
- E-Mail link for SUSE-SU-2018:1995-1
- SUSE Security Ratings
- SUSE Bug 1099310
- SUSE CVE CVE-2016-6252 page
Описание
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP1-LTSS:shadow-4.1.5.1-19.8.1
SUSE Linux Enterprise Server 12-LTSS:shadow-4.1.5.1-19.8.1
SUSE Linux Enterprise Server for SAP Applications 12 SP1:shadow-4.1.5.1-19.8.1
Ссылки
- CVE-2016-6252
- SUSE Bug 1099310
- SUSE Bug 979282